Simon Kelley, the dnsmasq maintainer, has announced six CVEs covering serious long-standing security vulnerabilities affecting nearly all non-ancient versions of dnsmasq. CERT is releasing the CVEs on May 11, 2026, with details and patches available on the dnsmasq website. A patched release, dnsmasq 2.92rel2, is available now, and a 2.93rc1 release candidate is imminent with a stable 2.93 targeted within a week. Kelley notes a surge in AI-generated security bug reports, which has significantly increased triage workload, and acknowledges that long embargoes are largely pointless given how quickly both good and bad actors can find these bugs using AI-based research tools.

3m read timeFrom lists.thekelleys.org.uk
Post cover image
513 Impressions