CVE-2026-5172 PUBLISHED

CVE-2026-5172

Assigner: certcc
Reserved: 30.03.2026 Published: 11.05.2026 Updated: 11.05.2026

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

Product Status

Vendor dnsmasq
Product dnsmasq
Versions
  • Version 2.92rel2 is affected

References

Problem Types

  • CWE-787: Out-of-bounds Write