CVE-2026-5172: exploitation status and patch state
CVE-2026-5172 · patch available
A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.
Is CVE-2026-5172 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.