CVE-2026-4892: exploitation status and patch state
CVE-2026-4892 · CVSS 8.4 HIGH
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.
Is CVE-2026-4892 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.