CVE-2026-5172: Dnsmasq
High severity, CVSS 7.3. EPSS: 0.7% chance of exploitation in the next 30 days.
A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.
Affected products
- Dnsmasq Dnsmasq: before 2.92rel2 (fixed in 2.92rel2)
- Red Hat Red Hat Enterprise Linux 10: before 0:2.90-7.el10_2 (fixed in 0:2.90-7.el10_2)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Openshift Container Platform 4
Published 2026-05-11. Last modified 2026-08-24.