Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-4892

Опубликовано: 11 мая 2026
Источник: debian
EPSS Низкий

Описание

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dnsmasqfixed2.92-5package

Примечания

  • https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html

  • https://xchglabs.com/blog/dnsmasq-five-cves.html

  • Fixed by: https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=10e6b5b83e80749cba7b090d7780b29f908f0571 (v2.93rc1)

EPSS

Процентиль: 53%
0.00812
Низкий

Связанные уязвимости

CVSS3: 8.4
ubuntu
3 месяца назад

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

CVSS3: 8.8
redhat
3 месяца назад

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

CVSS3: 8.4
nvd
3 месяца назад

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

msrc
2 месяца назад

CVE-2026-4892

CVSS3: 8.4
github
3 месяца назад

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

EPSS

Процентиль: 53%
0.00812
Низкий