CVE-2026-4893
An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.
- Affected products
- Linuxmint, Rocky Linux, Ubuntu, Dnsmasq
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 1.8% (77th percentile)
- NVD status
- Awaiting Analysis
- Published
- 2026-05-11
CVE-2026-4893 at NVD
2 known exploits for CVE-2026-4893
Proof-of-concept code and exploit modules indexed by Sploitus