VU#471747: dnsmasq contains several vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation
2026-05-12T20:52:07Z•648707f0c06c8cf4bc14872d51c6fe99cf28945445c031e029bd7c88cbf09a2b
AF_ALGCVE-trackingCasdoorCopy FailGGUFIAMLinux kernelOllamaRadware AlteonTerrariumarbitrary-file-writedhcpv6dnsdns-poisoningdnsmasqdnssecheap-corruptionheap-overflowinformation-disclosurelocal-privilege-escalationmemory-safetypath-traversalquantizationreflected-xsssandbox-escape
What happened
This document aggregates multiple vulnerability advisories published by CERT/CC affecting a range of open-source and commercial products. Notable issues include: dnsmasq multiple memory-safety and DNS poisoning/DoS flaws (CVE-2026-2291, CVE-2026-4890–4893, CVE-2026-5172) fixed in dnsmasq 2.92rel2; a Casdoor authenticated arbitrary file-write/path-traversal via unsanitized upload paths (CVE-2026-6815); the Linux "Copy Fail" local 4-byte page-cache write leading to reliable local root escalation (CVE-2026-31431); an unauthenticated Ollama GGUF quantization remote heap-memory disclosure (CVE-2026
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 648707f0c06c8cf4bc14872d51c6fe99cf28945445c031e029bd7c88cbf09a2b
- Enrichment time
- 2026-05-12T20:52:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.