Sploitus

CVE-2026-5172

2 known exploits for CVE-2026-5172

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

Affected products
Linuxmint, Ubuntu, Dnsmasq
CVSS 3.1
7.5 HIGH
EPSS
2.7% (85th percentile)
Weakness
CWE-125
NVD status
Awaiting Analysis
Published
2026-05-11
CVE-2026-5172 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-5172

Proof-of-concept code and exploit modules indexed by Sploitus