CVE-2026-5172
A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 2.7% (85th percentile)
- Weakness
- CWE-125
- NVD status
- Awaiting Analysis
- Published
- 2026-05-11
CVE-2026-5172 at NVD
2 known exploits for CVE-2026-5172
Proof-of-concept code and exploit modules indexed by Sploitus