[El-errata] ELSA-2026-19158 Important: Oracle Linux 10 dnsmasq security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Fri Jul 17 16:56:20 UTC 2026


Oracle Linux Security Advisory ELSA-2026-19158

http://linux.oracle.com/errata/ELSA-2026-19158.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
dnsmasq-2.90-7.el10_2.x86_64.rpm
dnsmasq-utils-2.90-7.el10_2.x86_64.rpm

aarch64:
dnsmasq-2.90-7.el10_2.aarch64.rpm
dnsmasq-utils-2.90-7.el10_2.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/dnsmasq-2.90-7.el10_2.src.rpm

Related CVEs:

CVE-2026-2291
CVE-2026-4890
CVE-2026-4891
CVE-2026-4892
CVE-2026-4893
CVE-2026-5172




Description of changes:

[2.90-7]
- Prevent overflow in extract_name function (CVE-2026-2291)
- Prevent DoS in DNSSEC validation (CVE-2026-4890)
- Prevent out-of-bounds read in DNSSEC validation (CVE-2026-4891)
- Prevent out-of-bounds write in DHCPv6 server (CVE-2026-4892)
- Prevent source check avoidance by RFC 7871 client-subnet (CVE-2026-4893)
- Prevent out-of-bounds read in extract_addresses (CVE-2026-5172)

[2.90-6]
- Prevent heap buffer overflow in cache via NAME_ESCAPE expansion
  (CVE-2026-2291)




More information about the El-errata mailing list