dns cache poisoning

  1. CVE-2026-2291 dnsmasq DNS Parsing Bug: Patch Focus for Windows-Hybrid Environments

    CVE-2026-2291 is a May 2026 dnsmasq vulnerability in the extract_name() DNS parsing code that can enable cache poisoning or denial of service in affected Linux and embedded resolver deployments, with Microsoft’s Security Update Guide carrying the record rather than shipping a Windows patch. That...
  2. CVE-2026-42960 Unbound DNS Cache Poisoning: Patch Unbound 1.25.1

    CVE-2026-42960 is a high-severity DNS cache-poisoning flaw in NLnet Labs Unbound through version 1.25.0, disclosed in May 2026 and patched in Unbound 1.25.1, with Microsoft’s Security Update Guide mirroring the advisory for environments that consume the resolver through Microsoft-managed or...