8.4
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.
Basic Information
ID
CVE-2026-4892
Source
certcc
Published
May 11, 2026 at 16:47
Modified
May 11, 2026 at 18:28
Affected Product
Vendor
dnsmasq
Product
dnsmasq
Version
2.92rel2
Affected Versions
dnsmasq dnsmasq 2.92rel2