Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-4892

Опубликовано: 11 мая 2026
Источник: debian

Описание

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dnsmasqfixed2.92-5package

Примечания

  • https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html

  • https://xchglabs.com/blog/dnsmasq-five-cves.html

  • Fixed by: https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=10e6b5b83e80749cba7b090d7780b29f908f0571 (v2.93rc1)

Связанные уязвимости

CVSS3: 8.4
ubuntu
4 месяца назад

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

CVSS3: 8.8
redhat
4 месяца назад

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

CVSS3: 8.4
nvd
4 месяца назад

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

msrc
4 месяца назад

CVE-2026-4892

CVSS3: 8.4
github
4 месяца назад

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.