Information Disclosure Vulnerability in dnsmasq by The Kelleys
CVE-2026-4893

5.3MEDIUM

Key Information:

Vendor

Dnsmasq

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-4893?

An information disclosure vulnerability has been identified in dnsmasq, enabling remote attackers to circumvent source checks by sending specially crafted DNS packets containing RFC 7871 client subnet information. This flaw could potentially expose sensitive information and compromise the integrity of DNS services.

Affected Version(s)

dnsmasq 2.92rel2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.