Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:1545 - Security Advisory
Issued:
2024-03-27
Updated:
2024-03-27

RHSA-2024:1545 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: dnsmasq security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for dnsmasq is now available for Red Hat Enterprise Linux 8.6 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The dnsmasq packages contain dnsmasq, a lightweight DNS (Domain Name Server) forwarder and DHCP (Dynamic Host Configuration Protocol) server.

Security Fixes:

  • dnsmasq: Heap use after free in dhcp6_no_relay (CVE-2022-0934)
  • dnsmasq: default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 (CVE-2023-28450)
  • dnsmasq: bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator (CVE-2023-50387)
  • dnsmasq: bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.6 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.6 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.6 ppc64le
  • Red Hat Enterprise Linux Server - TUS 8.6 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.6 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6 x86_64

Fixes

  • BZ - 2057075 - CVE-2022-0934 dnsmasq: Heap use after free in dhcp6_no_relay
  • BZ - 2178948 - CVE-2023-28450 dnsmasq: default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232
  • BZ - 2263914 - CVE-2023-50387 bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator
  • BZ - 2263917 - CVE-2023-50868 bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources

CVEs

  • CVE-2022-0934
  • CVE-2023-28450
  • CVE-2023-50387
  • CVE-2023-50868

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.6

SRPM
dnsmasq-2.79-21.el8_6.5.src.rpm SHA-256: 30b7db7d3615adaa91f13ae8e5bcb2efd12e8d501de59d914dba7fef15beaa6e
x86_64
dnsmasq-2.79-21.el8_6.5.x86_64.rpm SHA-256: 0057e4ea84630a88545c0313a32709cce8ef2f33680d55bf8ca03df14195fed6
dnsmasq-debuginfo-2.79-21.el8_6.5.x86_64.rpm SHA-256: efacbc20c51fd6c7674fe8f996bbfd705753492d50dbe79d98a190b7d7bfce8d
dnsmasq-debugsource-2.79-21.el8_6.5.x86_64.rpm SHA-256: befe61ba8c0bfd8f26f056b02c55766c7c525b400814c9b9d6ba3b29db179fc5
dnsmasq-utils-2.79-21.el8_6.5.x86_64.rpm SHA-256: c34966be7f234ba7d7946cd4b957087a76bc977e0e01eb617ce2dd85c5dfeff5
dnsmasq-utils-debuginfo-2.79-21.el8_6.5.x86_64.rpm SHA-256: ee6279cadf239522e19b886286ec9684d5c4fc3a50a578fd02cb3b67e9490fa6

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6

SRPM
dnsmasq-2.79-21.el8_6.5.src.rpm SHA-256: 30b7db7d3615adaa91f13ae8e5bcb2efd12e8d501de59d914dba7fef15beaa6e
x86_64
dnsmasq-2.79-21.el8_6.5.x86_64.rpm SHA-256: 0057e4ea84630a88545c0313a32709cce8ef2f33680d55bf8ca03df14195fed6
dnsmasq-debuginfo-2.79-21.el8_6.5.x86_64.rpm SHA-256: efacbc20c51fd6c7674fe8f996bbfd705753492d50dbe79d98a190b7d7bfce8d
dnsmasq-debugsource-2.79-21.el8_6.5.x86_64.rpm SHA-256: befe61ba8c0bfd8f26f056b02c55766c7c525b400814c9b9d6ba3b29db179fc5
dnsmasq-utils-2.79-21.el8_6.5.x86_64.rpm SHA-256: c34966be7f234ba7d7946cd4b957087a76bc977e0e01eb617ce2dd85c5dfeff5
dnsmasq-utils-debuginfo-2.79-21.el8_6.5.x86_64.rpm SHA-256: ee6279cadf239522e19b886286ec9684d5c4fc3a50a578fd02cb3b67e9490fa6

Red Hat Enterprise Linux Server - AUS 8.6

SRPM
dnsmasq-2.79-21.el8_6.5.src.rpm SHA-256: 30b7db7d3615adaa91f13ae8e5bcb2efd12e8d501de59d914dba7fef15beaa6e
x86_64
dnsmasq-2.79-21.el8_6.5.x86_64.rpm SHA-256: 0057e4ea84630a88545c0313a32709cce8ef2f33680d55bf8ca03df14195fed6
dnsmasq-debuginfo-2.79-21.el8_6.5.x86_64.rpm SHA-256: efacbc20c51fd6c7674fe8f996bbfd705753492d50dbe79d98a190b7d7bfce8d
dnsmasq-debugsource-2.79-21.el8_6.5.x86_64.rpm SHA-256: befe61ba8c0bfd8f26f056b02c55766c7c525b400814c9b9d6ba3b29db179fc5
dnsmasq-utils-2.79-21.el8_6.5.x86_64.rpm SHA-256: c34966be7f234ba7d7946cd4b957087a76bc977e0e01eb617ce2dd85c5dfeff5
dnsmasq-utils-debuginfo-2.79-21.el8_6.5.x86_64.rpm SHA-256: ee6279cadf239522e19b886286ec9684d5c4fc3a50a578fd02cb3b67e9490fa6

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.6

SRPM
dnsmasq-2.79-21.el8_6.5.src.rpm SHA-256: 30b7db7d3615adaa91f13ae8e5bcb2efd12e8d501de59d914dba7fef15beaa6e
s390x
dnsmasq-2.79-21.el8_6.5.s390x.rpm SHA-256: 63e80e1638f95760a9760f12a1e91357e0f31d94603d26a20019fe3ec446c2f7
dnsmasq-debuginfo-2.79-21.el8_6.5.s390x.rpm SHA-256: 39ec1176981bcf170c6cc691efe5a188a1af58d6de266b73b472454f728b56c4
dnsmasq-debugsource-2.79-21.el8_6.5.s390x.rpm SHA-256: 555d87174a6df05341f0177da8aecdc8a00f82e79cf4420b2d210ec1f8aa7baa
dnsmasq-utils-2.79-21.el8_6.5.s390x.rpm SHA-256: 9a2ac90cf75f707ac579ed3cb7a15af6a03bf67197c7413e3ca29416e346133a
dnsmasq-utils-debuginfo-2.79-21.el8_6.5.s390x.rpm SHA-256: 77243afe318be255764b196e60222bcfa73249435608b3aa0a75ec7d31f495ff

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.6

SRPM
dnsmasq-2.79-21.el8_6.5.src.rpm SHA-256: 30b7db7d3615adaa91f13ae8e5bcb2efd12e8d501de59d914dba7fef15beaa6e
ppc64le
dnsmasq-2.79-21.el8_6.5.ppc64le.rpm SHA-256: b0e468745314108e6571af745f2e025a6d9496ca51bed42d668f42c2aa247337
dnsmasq-debuginfo-2.79-21.el8_6.5.ppc64le.rpm SHA-256: ebf54d07b6d50584140d675ea9e6a30704c7cafb37d96d96b650b51f0167ee04
dnsmasq-debugsource-2.79-21.el8_6.5.ppc64le.rpm SHA-256: 153fd6f4ea408fc2b654e470e049f7144f28af43f2d417911b6740a4e10c68c2
dnsmasq-utils-2.79-21.el8_6.5.ppc64le.rpm SHA-256: e0724ed9a8babce6f2d46e4a47f12213ac01f170ff2db64cd629bbefbb4711a2
dnsmasq-utils-debuginfo-2.79-21.el8_6.5.ppc64le.rpm SHA-256: 963d5e2bab4392f14416fcbb1dfff8b6e4a0a133465ee020904ef832397c28fa

Red Hat Enterprise Linux Server - TUS 8.6

SRPM
dnsmasq-2.79-21.el8_6.5.src.rpm SHA-256: 30b7db7d3615adaa91f13ae8e5bcb2efd12e8d501de59d914dba7fef15beaa6e
x86_64
dnsmasq-2.79-21.el8_6.5.x86_64.rpm SHA-256: 0057e4ea84630a88545c0313a32709cce8ef2f33680d55bf8ca03df14195fed6
dnsmasq-debuginfo-2.79-21.el8_6.5.x86_64.rpm SHA-256: efacbc20c51fd6c7674fe8f996bbfd705753492d50dbe79d98a190b7d7bfce8d
dnsmasq-debugsource-2.79-21.el8_6.5.x86_64.rpm SHA-256: befe61ba8c0bfd8f26f056b02c55766c7c525b400814c9b9d6ba3b29db179fc5
dnsmasq-utils-2.79-21.el8_6.5.x86_64.rpm SHA-256: c34966be7f234ba7d7946cd4b957087a76bc977e0e01eb617ce2dd85c5dfeff5
dnsmasq-utils-debuginfo-2.79-21.el8_6.5.x86_64.rpm SHA-256: ee6279cadf239522e19b886286ec9684d5c4fc3a50a578fd02cb3b67e9490fa6

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.6

SRPM
dnsmasq-2.79-21.el8_6.5.src.rpm SHA-256: 30b7db7d3615adaa91f13ae8e5bcb2efd12e8d501de59d914dba7fef15beaa6e
aarch64
dnsmasq-2.79-21.el8_6.5.aarch64.rpm SHA-256: e800844907b6f923f4821bf369e3f061d4e64c45377f4cd458e48b60bd23f6c2
dnsmasq-debuginfo-2.79-21.el8_6.5.aarch64.rpm SHA-256: 08a38e5926de86b3759a7ac644f2f814b73d5f8e8815e0f9b13f732cd7b4e26e
dnsmasq-debugsource-2.79-21.el8_6.5.aarch64.rpm SHA-256: dbb4fdcc446c7135f1936bd45be84c9115d0085c6953bfb095441a4c89039258
dnsmasq-utils-2.79-21.el8_6.5.aarch64.rpm SHA-256: 7cfd09f11d4fa5f2029055c6fd9165900c192a848a6380c7b2109fb4e8fb226a
dnsmasq-utils-debuginfo-2.79-21.el8_6.5.aarch64.rpm SHA-256: 29db7acac930afdb90867f925ac32ec56209e61a508cf532cf09a5aa1a2c79cf

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6

SRPM
dnsmasq-2.79-21.el8_6.5.src.rpm SHA-256: 30b7db7d3615adaa91f13ae8e5bcb2efd12e8d501de59d914dba7fef15beaa6e
ppc64le
dnsmasq-2.79-21.el8_6.5.ppc64le.rpm SHA-256: b0e468745314108e6571af745f2e025a6d9496ca51bed42d668f42c2aa247337
dnsmasq-debuginfo-2.79-21.el8_6.5.ppc64le.rpm SHA-256: ebf54d07b6d50584140d675ea9e6a30704c7cafb37d96d96b650b51f0167ee04
dnsmasq-debugsource-2.79-21.el8_6.5.ppc64le.rpm SHA-256: 153fd6f4ea408fc2b654e470e049f7144f28af43f2d417911b6740a4e10c68c2
dnsmasq-utils-2.79-21.el8_6.5.ppc64le.rpm SHA-256: e0724ed9a8babce6f2d46e4a47f12213ac01f170ff2db64cd629bbefbb4711a2
dnsmasq-utils-debuginfo-2.79-21.el8_6.5.ppc64le.rpm SHA-256: 963d5e2bab4392f14416fcbb1dfff8b6e4a0a133465ee020904ef832397c28fa

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6

SRPM
dnsmasq-2.79-21.el8_6.5.src.rpm SHA-256: 30b7db7d3615adaa91f13ae8e5bcb2efd12e8d501de59d914dba7fef15beaa6e
x86_64
dnsmasq-2.79-21.el8_6.5.x86_64.rpm SHA-256: 0057e4ea84630a88545c0313a32709cce8ef2f33680d55bf8ca03df14195fed6
dnsmasq-debuginfo-2.79-21.el8_6.5.x86_64.rpm SHA-256: efacbc20c51fd6c7674fe8f996bbfd705753492d50dbe79d98a190b7d7bfce8d
dnsmasq-debugsource-2.79-21.el8_6.5.x86_64.rpm SHA-256: befe61ba8c0bfd8f26f056b02c55766c7c525b400814c9b9d6ba3b29db179fc5
dnsmasq-utils-2.79-21.el8_6.5.x86_64.rpm SHA-256: c34966be7f234ba7d7946cd4b957087a76bc977e0e01eb617ce2dd85c5dfeff5
dnsmasq-utils-debuginfo-2.79-21.el8_6.5.x86_64.rpm SHA-256: ee6279cadf239522e19b886286ec9684d5c4fc3a50a578fd02cb3b67e9490fa6

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility