Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4892

Опубликовано: 09 мая 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

A heap buffer overflow was discovered in dnsmasq's DHCP script helper process. When processing DHCPv6 client identifiers (CLIDs), the helper hex-encodes the raw CLID bytes into a fixed-size buffer without length validation. Since DHCPv6 CLIDs can be up to 65,535 bytes, a crafted DHCPv6 packet can overflow the buffer with attacker-controlled content. The helper process runs with root privileges.

Отчет

Red Hat rates this as Important. The overflow occurs in a root-privileged helper process with attacker-controlled content, and the --dhcp-script option is enabled by default in libvirt virtual network configurations, which affects RHEL systems using virt-manager, virt-install, or cockpit-machines. Exploitation requires the attacker to send crafted DHCPv6 packets from within the virtual network, meaning a malicious VM guest could potentially exploit this for host-level code execution as root.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6dnsmasqWill not fix
Red Hat Enterprise Linux 7dnsmasqAffected
Red Hat Enterprise Linux 10dnsmasqFixedRHSA-2026:1915819.05.2026
Red Hat Enterprise Linux 8dnsmasqFixedRHSA-2026:2058926.05.2026
Red Hat Enterprise Linux 9dnsmasqFixedRHSA-2026:1937319.05.2026
Red Hat Enterprise Linux 9.6 Extended Update SupportdnsmasqFixedRHSA-2026:3450801.07.2026
Red Hat OpenShift Container Platform 4.19rhcos-4.19.9.6.202607151909FixedRHSA-2026:4076222.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2458518dnsmasq: DHCPv6 CLID buffer overflow in helper process

EPSS

Процентиль: 53%
0.00812
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
ubuntu
3 месяца назад

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

CVSS3: 8.4
nvd
3 месяца назад

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

msrc
2 месяца назад

CVE-2026-4892

CVSS3: 8.4
debian
3 месяца назад

A heap-based out-of-bounds write vulnerability in the DHCPv6 implement ...

CVSS3: 8.4
github
3 месяца назад

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

EPSS

Процентиль: 53%
0.00812
Низкий

8.8 High

CVSS3