VU#471747: dnsmasq contains several vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation

2026-05-12T20:52:07Z648707f0c06c8cf4bc14872d51c6fe99cf28945445c031e029bd7c88cbf09a2b
AF_ALGCVE-trackingCasdoorCopy FailGGUFIAMLinux kernelOllamaRadware AlteonTerrariumarbitrary-file-writedhcpv6dnsdns-poisoningdnsmasqdnssecheap-corruptionheap-overflowinformation-disclosurelocal-privilege-escalationmemory-safetypath-traversalquantizationreflected-xsssandbox-escape

What happened

This document aggregates multiple vulnerability advisories published by CERT/CC affecting a range of open-source and commercial products. Notable issues include: dnsmasq multiple memory-safety and DNS poisoning/DoS flaws (CVE-2026-2291, CVE-2026-4890–4893, CVE-2026-5172) fixed in dnsmasq 2.92rel2; a Casdoor authenticated arbitrary file-write/path-traversal via unsanitized upload paths (CVE-2026-6815); the Linux "Copy Fail" local 4-byte page-cache write leading to reliable local root escalation (CVE-2026-31431); an unauthenticated Ollama GGUF quantization remote heap-memory disclosure (CVE-2026

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
648707f0c06c8cf4bc14872d51c6fe99cf28945445c031e029bd7c88cbf09a2b
Enrichment time
2026-05-12T20:52:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#471747: dnsmasq contains several vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation · Baitaphish