Heap-Based Out-of-Bounds Write Vulnerability in dnsmasq by TheKelleys
CVE-2026-4892

8.4HIGH

Key Information:

Vendor

Dnsmasq

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-4892?

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq can be exploited by local attackers. By sending crafted DHCPv6 packets, an attacker can execute arbitrary code with root privileges. This poses a significant risk, especially in environments where dnsmasq is utilized for network infrastructure services.

Affected Version(s)

dnsmasq 2.92rel2

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.