-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 10 Jun 2026 15:03:09 +0700
Source: dnsmasq
Architecture: source
Version: 2.85-1+deb11u2
Distribution: bullseye-security
Urgency: medium
Maintainer: Simon Kelley <simon@thekelleys.org.uk>
Changed-By: Arnaud Rebillout <arnaudr@debian.org>
Changes:
dnsmasq (2.85-1+deb11u2) bullseye-security; urgency=medium
.
* Non-maintainer upload by the LTS Team.
* Import upstream patches to fix the following CVEs:
- CVE-2026-2291: Fix buffer overflow in struct bigname.
- CVE-2026-4890: Fix NSEC bitmap parsing infinite loop.
- CVE-2026-4891: Verify rdlen field in RRSIG packets.
- CVE-2026-4892: Fix buffer overflow in helper.c with large CLIDs.
- CVE-2026-4893: Fix broken client subnet validation.
* Sync autopkgtests with bookworm
Checksums-Sha1:
1faa0429d3d760d445d2e96bc8f530cd8d1f07c4 2390 dnsmasq_2.85-1+deb11u2.dsc
3c69e8a26b859243bc83850fee3d6ac00f10fe41 747392 dnsmasq_2.85.orig.tar.gz
ed96f3de3b4d382acef03124d6db4b16f1460628 48312 dnsmasq_2.85-1+deb11u2.debian.tar.xz
1302fcce575c72bc6d9cfe74a9a95140734bfe67 5584 dnsmasq_2.85-1+deb11u2_source.buildinfo
Checksums-Sha256:
2c0c29f274f95c8f423d5c2135921af529921890c2cf22365abc81d51f68bf36 2390 dnsmasq_2.85-1+deb11u2.dsc
1ce37015ffa8abd55aeaf6183bd3ed72627f503c2f6cd9b38639df2af5b1796f 747392 dnsmasq_2.85.orig.tar.gz
0eca19c16b379f3f4ebd44d27526d0ca36498b4a4c8d1d491907286b68192a0d 48312 dnsmasq_2.85-1+deb11u2.debian.tar.xz
8ceeef8bd5688e8b432b5071bff1d518010c28489406d98cea3fb9c062ce180d 5584 dnsmasq_2.85-1+deb11u2_source.buildinfo
Files:
2ad5c033e02dcd2112b83cb05deaa293 2390 net optional dnsmasq_2.85-1+deb11u2.dsc
1517b24d29d68f0e3190562f31139b13 747392 net optional dnsmasq_2.85.orig.tar.gz
5ca9464e8cc7a6cd2fb23fca275537b7 48312 net optional dnsmasq_2.85-1+deb11u2.debian.tar.xz
c1394ac96eff6816b4e5c84f95ade778 5584 net optional dnsmasq_2.85-1+deb11u2_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJHBAEBCgAxFiEE0Kl7ndbut+9n4bYs5yXoeRRgAhYFAmopMDETHGFybmF1ZHJA
ZGViaWFuLm9yZwAKCRDnJeh5FGACFrvUD/47p4vxohSllKBbrMcN2A0bAhiB+YWr
mROtE3WpkBRiZ/9g+vhGC/3urU8fMVJwMbggof/s+ce2B3Jhsupvg9LYJ1KNiIv+
t6drAkzV4dHS61OAxm8CAJNdG5vonc0QOxExmYDJvKSNbKhD1PZlkPHlngAe30dH
k/RHYZYM66FAd7VbjUr9JZesgL4XLzWCUVaiST2HSIKhWzxNczTZjCLwO8L1esH/
VGcO6FGwlisGx7V3pSaRzs7aa7VQmZ7yYldEr63VlZRhms1h+hwAMDcsE1eJiuFr
uSBS0TPvGiTOkmlgHKA8Ts8pJs6Jy+8UNTtEbv/xqR5IMXcuHvodhg7QYWQJw0mn
S4zGbWkD/4wbwOT0vfOJzOyUb5o6cKc0CCO9ZJ0fKy4wm3kF1OeywdZeVygRrEHt
udDP8vfQ61LTSN1ox82URs7K50oWJDzjM5qIzuU5d+1ntQU2HIgHFs6sFjNfMMrV
iOHZ80EoYpKsYHytKtPjFj3OzXIvRKSVy4K27B1esCfrXOioZQ3r0TicrCrxpI3j
hvdEgLWBm/wT1vOyvslsF5BAVsKTn0y/DzLahJlnHrEebECmtfGsptCQSDuN44Kr
ajhDsywKfIvbMi2ADzoB8ZzE/290Drd1qI9/mjXC/ucQEDTtPkFNCLk9n4eG4cS/
cYlt60wU7kty7Q==
=mQKv
-----END PGP SIGNATURE-----