Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package dnsmasq for openSUSE:Factory checked in at 2026-05-20 15:23:08 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/dnsmasq (Old) and /work/SRC/openSUSE:Factory/.dnsmasq.new.1966 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "dnsmasq" Wed May 20 15:23:08 2026 rev:106 rq:1353993 version:2.92rel2 Changes: -------- --- /work/SRC/openSUSE:Factory/dnsmasq/dnsmasq.changes 2026-04-23 17:09:20.836440201 +0200 +++ /work/SRC/openSUSE:Factory/.dnsmasq.new.1966/dnsmasq.changes 2026-05-20 15:23:33.523763092 +0200 @@ -1,0 +2,18 @@ +Tue May 12 09:06:00 UTC 2026 - Reinhard Max <[email protected]> + +- Update to security release 2.92rel2: + * CVE-2026-2291, bsc#1258251: dnsmasq can be abused to record + false cached data enabling DoS or attacker redirect. + * CVE-2026-4890, bsc#1265001: DoS vulnerability in the DNSSEC + validation. + * CVE-2026-4891, bsc#1265002: heap-based out-of-bounds read + vulnerability in the DNSSEC validation. + * CVE-2026-4892, bsc#1265003: heap-based out-of-bounds write + vulnerability in the DHCPv6 implementation. + * CVE-2026-4893, bsc#1265004: information disclosure + vulnerability in dnsmasq allows remote attackers to bypass + source checks. + * CVE-2026-5172, bsc#1265006: buffer overflow in dnsmasq’s + extract_addresses() function. + +------------------------------------------------------------------- Old: ---- dnsmasq-2.92.tar.xz dnsmasq-2.92.tar.xz.asc New: ---- dnsmasq-2.92rel2.tar.xz dnsmasq-2.92rel2.tar.xz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ dnsmasq.spec ++++++ --- /var/tmp/diff_new_pack.imPnYh/_old 2026-05-20 15:23:34.179790073 +0200 +++ /var/tmp/diff_new_pack.imPnYh/_new 2026-05-20 15:23:34.183790237 +0200 @@ -27,7 +27,7 @@ %define dnsmasq_group nogroup %endif Name: dnsmasq -Version: 2.92 +Version: 2.92rel2 Release: 0 Summary: DNS Forwarder and DHCP Server License: GPL-2.0-only OR GPL-3.0-only
