{
  "cves": [
    "CVE-2026-2291",
    "CVE-2026-4890",
    "CVE-2026-4891",
    "CVE-2026-4892",
    "CVE-2026-4893",
    "CVE-2026-5172"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[2.90-7]\n- Prevent overflow in extract_name function (CVE-2026-2291)\n- Prevent DoS in DNSSEC validation (CVE-2026-4890)\n- Prevent out-of-bounds read in DNSSEC validation (CVE-2026-4891)\n- Prevent out-of-bounds write in DHCPv6 server (CVE-2026-4892)\n- Prevent source check avoidance by RFC 7871 client-subnet (CVE-2026-4893)\n- Prevent out-of-bounds read in extract_addresses (CVE-2026-5172)\n\n[2.90-6]\n- Prevent heap buffer overflow in cache via NAME_ESCAPE expansion\n  (CVE-2026-2291)",
  "id": "ELSA-2026-19158",
  "ovalId": "oval:com.oracle.elsa:def:202619158",
  "source": "oracle_linux",
  "title": "ELSA-2026-19158:  dnsmasq security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-19158.html"
}