CVE-2026-4892

HIGH8.4EPSS 0.01%
Published: 5/11/2026Modified: 5/14/2026
Also known as:ALPINE-CVE-2026-4892

Description

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (2)