CVE-2026-5172
dnsmasq dnsmasq, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6
A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.
- CVSS
- 7.3
- EPSS
- 2.68% 84.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.12