dnsmasq 中存在六个严重安全漏洞的 CVE

Lobsters Hottest 新闻

摘要

在 dnsmasq 中发现了六个严重安全漏洞(CVE),影响了大多数非远古版本。Simon Kelley 已发布 2.92rel2 版本并提供了补丁,同时宣布即将发布 2.93 版本以解决这些长期存在的 bug。

<p><a href="https://lobste.rs/s/tvhqam/six_cves_for_serious_security">评论</a></p>
查看原文
查看缓存全文

缓存时间: 2026/05/13 00:22

# [Dnsmasq-discuss] 安全 - 重要 来源:https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html **Simon Kelley**[simon at thekelleys\.org\.uk](mailto:dnsmasq-discuss%40lists.thekelleys.org.uk?Subject=Re%3A%20%5BDnsmasq-discuss%5D%20Security%20-%20IMPORTANT&In-Reply-To=%3C2049e528-8136-462f-ab01-caca320bddc1%40thekelleys.org.uk%3E) *2026年5月11日 星期一 17:18:25 UTC*- 上一封邮件(按主题):[\[Dnsmasq\-discuss\] DHCP 请求中 circuit-id 匹配问题](https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018470.html) - 下一封邮件(按主题):[\[Dnsmasq\-discuss\] 格式错误的 RRSIG 可导致 dnsmasq 崩溃](https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018472.html) - **邮件排序方式:**[\[ 日期 \]](https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/date.html#18471)[\[ 主题 \]](https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/thread.html#18471)[\[ 标题 \]](https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/subject.html#18471)[\[ 作者 \]](https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/author.html#18471) --- `` 今天(2026年5月11日),CERT 将发布针对 dnsmasq 中严重安全漏洞的六个 CVE。这些都是长期存在的 bug,几乎适用于所有非古老版本。相关 CVE 已提前向供应商披露,希望他们能及时发布修补后的 dnsmasq 软件包。 详细信息和补丁可在以下网站获取: https://thekelleys.org.uk/dnsmasq/CVE/ 我已经发布了当前稳定版 2.92 的 "2.92rel2" 版本,该版本已应用上述补丁,可从常规渠道下载。 同时,修复开发分支中这些 bug 的代码提交也将上传。其中一些使用了与后向移植相同的补丁,但另一些则是更全面的重写,以解决根本原因。 基于 AI 的安全研究经历了一场变革,在过去几个月里,我花了大量时间处理 bug 报告,剔除重复项(重复项太多了!),并对 bug 进行分类,区分哪些需要向供应商提前披露,哪些更适合立即公开并修复。这些判断必然是主观的,但考虑到“好人”发现这些 bug 的次数之多,毫无疑问“坏人”也能做到同样的事情,因此长期的保密期似乎有些毫无意义。此外,所有相关方协调保密期并提供后向移植所需的时间和精力也是巨大的。我认为大多数 bug 的优先事项是向前推进修复工作,并尽可能使新的 dnsmasq 版本无 bug。为此,你可能已经注意到,在本公告发布前的几周里,git 仓库中出现了大量安全修复提交。 我很快就会标记 dnsmasq-2.93rc1,目标是尽快完成稳定的 2.93 版本发布。社区成员对候选版本的测试至关重要,我鼓励大家尽早参与测试。如果顺利,2.93 版本可能在一周左右发布。 AI 生成的 bug 报告潮毫无停歇迹象,因此这一过程很可能很快就要再次重复。在尽可能多地将持续涌入的 bug 修复纳入 2.93 与确保其及时发布之间存在着张力。我计划优先考虑及时性,并在发布后继续按需开展工作。 Simon. `` --- - 上一封邮件(按主题):[\[Dnsmasq\-discuss\] DHCP 请求中 circuit-id 匹配问题](https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018470.html) - 下一封邮件(按主题):[\[Dnsmasq\-discuss\] 格式错误的 RRSIG 可导致 dnsmasq 崩溃](https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018472.html) - **邮件排序方式:**[\[ 日期 \]](https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/date.html#18471)[\[ 主题 \]](https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/thread.html#18471)[\[ 标题 \]](https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/subject.html#18471)[\[ 作者 \]](https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/author.html#18471) --- 更多有关 Dnsmasq\-discuss 邮件列表的信息 (https://lists.thekelleys.org.uk/cgi-bin/mailman/listinfo/dnsmasq-discuss)

相似文章

@Dinosn: Dnsmasq DNS远程堆缓冲区溢出

X AI KOLs Timeline

Dnsmasq中的一个堆缓冲区溢出漏洞(CVE-2026-2291)允许通过恶意上游DNS服务器进行远程代码执行。该问题在2.73版本中引入,并在2.92rel2和2.93版本中修复。