[ubuntu/noble-security] dnsmasq 2.90-2ubuntu0.4 (Accepted)
Kyle Kernick
kyle.kernick at canonical.com
Tue Jul 14 16:26:27 UTC 2026
dnsmasq (2.90-2ubuntu0.4) noble-security; urgency=medium
* SECURITY UPDATE: Buffer overflow in log_query.
- debian/patches/CVE-2026-12725.patch: Account for the "not supported"
string in logs, and add checks to catch overflow in src/cache.c and
src/dnssec.c
- CVE-2026-12725
* SECURITY UPDATE: Buffer OOB read in find_soa.
- debian/patches/CVE-2026-12969.patch: change the extrabytes argument
from 0 to 10 in src/rfc1035.c
- CVE-2026-12969
Date: 2026-07-13 22:51:19.229553+00:00
Changed-By: Kyle Kernick <kyle.kernick at canonical.com>
https://launchpad.net/ubuntu/+source/dnsmasq/2.90-2ubuntu0.4
-------------- next part --------------
Sorry, changesfile not available.
More information about the noble-changes
mailing list