-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 02 May 2026 18:37:29 +0200 Source: dnsmasq Binary: dnsmasq-base dnsmasq-base-dbgsym dnsmasq-base-lua dnsmasq-base-lua-dbgsym dnsmasq-utils dnsmasq-utils-dbgsym Architecture: i386 Version: 2.90-4~deb12u2 Distribution: bookworm-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Sven Geuer Description: dnsmasq-base - Small caching DNS proxy and DHCP/TFTP server - executable dnsmasq-base-lua - Small caching DNS proxy and DHCP/TFTP server - executable, Lua-en dnsmasq-utils - Utilities for manipulating DHCP leases Changes: dnsmasq (2.90-4~deb12u2) bookworm-security; urgency=high . * d/p/*: - CVE-2026-2291.patch: Fix buffer overflow in struct bigname. - CVE-2026-4890.patch: Fix NSEC bitmap parsing infinite loop. - CVE-2026-4891.patch: Verify rdlen field in RRSIG packets. - CVE-2026-4892.patch: Fix buffer overflow in helper.c with large CLIDs. - CVE-2026-4893.patch: Fix broken client subnet validation. - CVE-2026-5172.patch: Fix buffer overflow vulnerability in extract_addresses(). Checksums-Sha1: 3c9a4d01b3d587dc49c598c60287586f6e1c07a1 537692 dnsmasq-base-dbgsym_2.90-4~deb12u2_i386.deb 01ea2d46cf9e8a6878cdb2cc9f3b952a7404ce00 540372 dnsmasq-base-lua-dbgsym_2.90-4~deb12u2_i386.deb 734ffd609a241bde8b6ec1b87a2099092ae5f917 510072 dnsmasq-base-lua_2.90-4~deb12u2_i386.deb 5e77ee2ad2f7f2cb348671c204249c94a681daf9 508420 dnsmasq-base_2.90-4~deb12u2_i386.deb e48e57c8c8b8cc3f96076877c302d1c94e424964 27380 dnsmasq-utils-dbgsym_2.90-4~deb12u2_i386.deb d09243da03c213f9129e712e0383bb26a23513a2 59820 dnsmasq-utils_2.90-4~deb12u2_i386.deb 7c02c807284f29f1ebd34177696b5d04a28998de 8616 dnsmasq_2.90-4~deb12u2_i386-buildd.buildinfo Checksums-Sha256: ee51aa6be2ea4d99cf40a6f281a2ce26efc8463cd2cbfc7c53d2630340149113 537692 dnsmasq-base-dbgsym_2.90-4~deb12u2_i386.deb 1157f1644f6c9696b950a379d58b9e5bc7feff9a48ce84a991c637b0060c9b65 540372 dnsmasq-base-lua-dbgsym_2.90-4~deb12u2_i386.deb d6b93c170dceff7248fd52065047fe6c3f383ccab9e1109d98e2160a1b437d67 510072 dnsmasq-base-lua_2.90-4~deb12u2_i386.deb 4632a803055976fe9de2b264ac8849437fecc9459fd80ff53371ab5b647ea944 508420 dnsmasq-base_2.90-4~deb12u2_i386.deb ed62087759fa8ff8ea3a4adda09e023de09865bdf79eefa61c0f483b7e079635 27380 dnsmasq-utils-dbgsym_2.90-4~deb12u2_i386.deb 57b698be74a18241277866fe80f93ede3cd7956464eba1fa6512cff7bab4c54c 59820 dnsmasq-utils_2.90-4~deb12u2_i386.deb 3507e6d97031be6fa05c0f1aecad4d024f2b04510e8be74595275ba828be020a 8616 dnsmasq_2.90-4~deb12u2_i386-buildd.buildinfo Files: 8837ddec1b62315c247b1374dde428f7 537692 debug optional dnsmasq-base-dbgsym_2.90-4~deb12u2_i386.deb bf49350ff52f7e34a671bf18296aa3a5 540372 debug optional dnsmasq-base-lua-dbgsym_2.90-4~deb12u2_i386.deb 2fcb18c35e0a27435e5ad6becafc5248 510072 net optional dnsmasq-base-lua_2.90-4~deb12u2_i386.deb 98b1f904fd6a619934db61f4a705b7f8 508420 net optional dnsmasq-base_2.90-4~deb12u2_i386.deb 04ff7150e8020447a788acef02377db2 27380 debug optional dnsmasq-utils-dbgsym_2.90-4~deb12u2_i386.deb cf5fb03433eb0cd2f1db6918c92983ef 59820 net optional dnsmasq-utils_2.90-4~deb12u2_i386.deb d7e4b0b3d977a8075df0b7ee7752e691 8616 net optional dnsmasq_2.90-4~deb12u2_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7cQ9mRD4+dWjjrb6PkCWRKsh20cFAmn4hWgACgkQPkCWRKsh 20fl6Q//TWQ+7DevVJPxjN66vlpTiHVxFvIkxavWIpwqj61QhdkWiLdrzZ+t7J6O zoMhc2SSJEqorcqPrLI9DpKyNMna/JgDE3YJ8kNU+o/aXksVV6NLpucGotGA1aKI Edi0Yk0SDn9hL0/k7Zl93ety4dfYuCDaF/7dOlKKyZA3tLm/KFGbEwLpB0X8b94F dVcvN/MeWkI+3PYWj/QUCo94RyOJVTWccxRpTOaPGt1Dh4aVCbWmJWPTzms6TEQw r249EjBH1I1IluLEH4oPIOMI1KlYyDwCFuq8XA0k+HqqysA90F7obf+3+Q8Ws+Tq Xl/YfffvoU/vWFQePD8QVhIyQUbU/62V7BEMbn3a7f6GghgDEHFgLb4BB+ts4hCh xaVjFflTUmUW5bBFdVcNBFsn41Ig/4SCOYABDNckqZiVOTilZGU8ZKYu4XBSQxWq bABbtR1jSV+dtIZFnKI3WwUvTpkvJp5UElCTiTrp5OQKv44X/7josaC0GoXYUbgK +qU4mnZ1pSuyPc8pDiVMviZgcN0NqFjXHmBNNGCA33Lcf1zalwIwk4B/VTdqpAdk fTGXsGaunp6+Ws55uCydaeokVn/l+rDusTdLhvisRv5VUHrUClWRjWSaXMrO1A7Y B3lePnK9WAEpnJKNoALhNE4K8U02+lPjl/Tidrs9iH+memjOyBI= =4AxC -----END PGP SIGNATURE-----