CVE-2026-4892: Dnsmasq
High severity, CVSS 8.4. EPSS: 0.3% chance of exploitation in the next 30 days.
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.
Affected products
- Dnsmasq Dnsmasq: before 2.92rel2 (fixed in 2.92rel2)
- Red Hat Red Hat Enterprise Linux 10: before 0:2.90-7.el10_2 (fixed in 0:2.90-7.el10_2)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8: before 0:2.79-36.el8_10 (fixed in 0:2.79-36.el8_10)
- Red Hat Red Hat Enterprise Linux 9: before 0:2.85-18.el9_8.1 (fixed in 0:2.85-18.el9_8.1)
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:2.85-17.el9_6.1 (fixed in 0:2.85-17.el9_6.1)
- Red Hat Red Hat Openshift Container Platform 4.19: before 4.19.9.6.202607151909-0 (fixed in 4.19.9.6.202607151909-0)
Published 2026-05-11. Last modified 2026-08-25.