#DNSMASQ
🚨 EUVD-2026-84099
📊 8.8/10
🏢 OpenWRT

📝 luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84099

#cybersecurity #infosec #cve #euvd
September 29, 2026 at 3:00 PM
> USN-8833-1: libvirt vulnerabilities
https://ubuntu.com/security/notices/USN-8833-1
USN-8833-1: libvirt vulnerabilities
It was discovered that libvirt did not properly validate newline characters in DNS TXT record values and SRV record attributes in its virtual network driver. A local attacker with permission to define virtual networks could possibly use this issue to inject arbitrary dnsmasq configuration directives, leading to arbitrary command execution as root. (CVE-2026-61477) It was discovered that libvirt did not properly handle errors during XML context parsing. An attacker could possibly use this issue to cause libvirt to crash, resulting in a denial of service. (CVE-2026-61478) He Wei discovered that libvirt had a symlink-following vulnerability in the file ownership change function used for virtual TPM state directories. A local attacker running as the swtpm user could possibly use this issue to cause libvirt to change the ownership of an arbitrary file, leading to privilege escalation. (CVE-2026-63622) It was discovered that libvirt created storage volume images with overly permissive permissions during clone or convert operations. A local attacker could possibly use this issue to read guest disk contents, resulting in information disclosure. (CVE-2026-63623) It was discovered that libvirt had an integer overflow in the NodeGetFreePages RPC handler. A local attacker could possibly use this issue to cause libvirt to crash or execute arbitrary code. (CVE-2026-18917) It was discovered that libvirt had a symlink-following flaw in the virtual TPM emulator setup function. A local attacker with access to the swtpm account could possibly use this issue to cause libvirt to change the ownership of an arbitrary file, leading to privilege escalation. (CVE-2026-77159)
ubuntu.com
September 28, 2026 at 3:40 PM
光10Gbpsに設定変更に先立ってルーターを購入したので置き換えた。
古いルーターにopenwrtを入れてdhcpと
dnsmasqを運用していたのはRaspberry Piに移行して廃止した。Netgearの
古いSwitchも撤去してシンプルな構成に出来たかな。
September 27, 2026 at 6:56 AM
メモ:CloudFlareのIPv6 DNSは
2606:4700:4700::1111
あとで設定する
けどNEC IXのIPv6 DNS-Proxyの設定方法と、dnsmasqでv6吹く方法も調べないとなぁ
September 23, 2026 at 2:29 AM
20 хвилинна пригода, поставить dnsmasq щоб на тілібоні в локальній мережі резолвився сервачок і пакетики бігали по https
сука я щас завию нахуй
September 18, 2026 at 9:08 PM
Oh yeah if you're also a Linux sicko: install dnsmasq and resolvconf and watch your Steam download speeds quadruple. There's an ollllllllld bug in the Linux client and having a local DNS cache avoids it.
what do you mean it's 100 gigs
September 18, 2026 at 1:12 AM
Some settings weren't importing properly and on top of it all, some features were eol and discontinued so I had to look up how to migrate over things onto new stuff.

Example being the ISC IPv4 no longer being a thing that I had to reinstall it as a legacy plugin to copy over and put it on dnsmasq.
September 14, 2026 at 8:42 PM
Debian 13.7 "trixie" lands with fixes from 92 security advisories and updates to 106 packages, including 6 Linux kernel advisories plus major updates for glibc, qemu, imagemagick, wolfssl, perl, and cyrus-imapd. #Debian #LinuxKernel #trixie
Debian 13.7 Ships The Fixes Behind 92 Security Advisories, Updates 106 Packages
Debian 13.7 “trixie” bundles 92 previously issued security advisories and fixes 106 source packages, including six Linux kernel advisories and major updates across glibc, qemu, imagemagick, wolfssl, perl, and cyrus-imapd. The point release also addresses issues in u-boot, sbsigntool, flask, dnsmasq, python3.13, bettercap, and onionshare, while updating the installer and kernel ABI to 6.12.107+deb13. #Debian13.7 #trixie #LinuxKernel #glibc #qemu #imagemagick #wolfssl #perl #cyrus-imapd #u-boot #sbsigntool #flask #dnsmasq #python3.13 #bettercap #onionshare
www.hendryadrian.com
September 14, 2026 at 8:45 AM
dnsmasq is not just a DNS resolver, but is one of the most popular DHCP+TFTP packages for the server side of PXEbooting. Except, buddy, I already got DNS. Running "dnsmasq but hold the dns" just sounds incredibly stupid, even if it makes sense in context 🤪
September 13, 2026 at 5:29 AM
ah no yes it is... dnsmasq...
September 12, 2026 at 10:51 PM
I don't think my 2018 LG could do this, but, I have it on the guest Wi-Fi because I don't trust it. I also blocked a few of its contacts (which I watched immediately upon making it live) DNS names in my ASUS router dnsmasq.
Yet another reason why I'm hanging onto my ancient "dumb TV" as,long as I can.
September 8, 2026 at 5:19 AM
By the way, for a few more technical details:
- The Pi's built-in adapter has terrible range, so it's using a Panda Wireless PAU0D adapter
- hostapd is used to create an access point with 802.11ac extensions, since NetworkManager can't do that for some reason
- dnsmasq is used to assign IP […]
Original post on fuzzyfox.social
fuzzyfox.social
September 7, 2026 at 6:08 PM
Spent the night on a crashcourse on nmcli and dnsmasq, all you need to spin up a quick subnet with ethernet connected NAS

Big caveat - you can delete UGOS and boot with different distro, but you can't get firmware updates without it. And UGOS image is only available through their customer service.
September 7, 2026 at 10:41 AM
Nooo my access point trap didn't work today because dnsmasq tried to start before the interface was ready, so it failed, and it didn't retry :(

Fixed the service so that it'll restart on failure, but I probably could've gotten a lot of people today...
September 6, 2026 at 4:46 AM
they're probably gonna think it's me even tho i've been off of bsky and discord and signal for the last like 12 hours bc i spent all night updating my opnsense firewall and migrating from isc to dnsmasq and u do this 2 me
September 5, 2026 at 6:15 PM
Setting up a refurbished laptop with Linux, I had no USB sticks to boot from, dnsmasq and PXE to the rescue!
September 5, 2026 at 6:11 AM
For _years_ now I’ve been adding each local service’s subdomain as a separate entry in dnsmasq pointing to the same IP where the reverse proxy is hosted. Last night it (finally) occurred to me that I could just have a single entry for the whole domain. :blobfoxfacepalm:
September 3, 2026 at 4:21 PM
🔥 Serious dnsmasq security vulnerabilities exposed
The CERT has released six CVEs for serious security vulnerabilities in dnsmasq, a popular DNS forwarder and DHCP server. These vulnerab...

🌐 aitechcodex.uk/news/1445/?utm_source=bluesky&utm_medium=social&utm_campaign=daily_news 📡 t.me/AITechNewsUK
August 29, 2026 at 5:01 AM
I am just starting to write my Proxmox configuration app. already got the DNS app to work. Probs got that as far as it needs to go for me in that it works with DNSmasq. Now all DNS names at a IP are on the same line with the VM getting the PTR. much more tidy DNS now.
August 24, 2026 at 6:12 PM
Implicit here is that I have DNSMasq provisioning internal DNS records based on DHCP client IDs (and whatever else gets sent along in DHCP, I don't know exactly how it infers it). If it matters, the router is a unifi router, but I am also interested in solutions to this problem that use OpenWRT […]
Original post on mastodon.social
mastodon.social
August 23, 2026 at 2:12 AM
new gfeh (Object Storage) coming. also install is trying to use rolodex for libvirt stuff instead of dnsmasq -- might be buggy at first but there's some cache seeding/sharing opportunities there once the vm and libvirt work together.

probably still a few bugs around plex -- oauth once don't purge
August 17, 2026 at 4:33 AM