CVE-2026-4892Disclosure

LOWCVSS 8.4 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-13)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-11: 1Mentions · 2026-05-13: 2Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-13: 205-1105-13
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-111
Disclosure1
2026-05-132
Disclosure2
Full discourse3 posts
  • hito@_hito_
    Disclosure

    CVE-2026-4892、https://bugzilla.redhat.com/show_bug.cgi?id=2458518 "In helper.c:265, the DHCPv6 CLID is hex-encoded via sprintf("%.2x") into daemon->packet (5,131 bytes) with no length cap on the CLID. DHCPv6 CLIDs can be up to 65,535 bytes (131,070 hex characters). The helper process retains root privileges. log6_packet() already caps CLID to 100 bytes for logging, but the helper code path was missed. Fix: add && i < 100 bound to the encoding loop, matching the logging cap."

    Post summary

    The passage discloses CVE‑2026‑4892, describing an unbounded DHCPv6 CLID handling that allows oversized data and root privilege retention, and it includes the specific mitigation fix.

    03051405
    2.2K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    Dnsmasqに複数のメモリ脆弱性。CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, CVE-2026-4893, CVE-2026-5172の6件。CVE-2026-4892はDHCPv6パケットでのroot権限任意コード実行。他の影響はキャッシュポイズニング、DoS、情報漏洩。 https://securityonline.info/multiple-memory-flaws-in-dnsmasq-threaten-millions-of-connected-devices/

    Post summary

    Several memory vulnerabilities in dnsmasq were disclosed, including a CVE that permits arbitrary root code execution through DHCPv6 packets, alongside cache poisoning, DoS, and information leakage risks.

    010521.2K
    7.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4892 A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a craft… https://www.cve.org/CVERecord?id=CVE-2026-4892

    Post summary

    A brief disclosure of CVE-2026-4892 is given, describing it as a heap-based out-of-bounds write in dnsmasq that can allow local attackers to gain root-level code execution; no PoC, exploit, patch, or active exploitation is referenced.

    0000087
    57.5K followersView on X

Explore more