Overview
What is CVE-2026-4892?
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.
Vulnerability intelligence
CVE-2026-4892 and is rated High severity with a CVSS score of 8.4. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.