PT-2026-43620 · Radvd · Radvd

·

CVE-2026-48715

·

Published

2026-05-26

·

Updated

2026-07-21

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions radvd versions prior to 2.21
Description The radvdump utility contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, the print ff() function copies up to 2032 bytes of attacker-controlled packet data into a 16-byte struct in6 addr on the stack, resulting in an overflow of up to 2016 bytes. The main radvd daemon is not affected.
Recommendations Update to version 2.21.

Exploit

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48715
GHSA-52PX-GH9P-M379
OESA-2026-2807
OESA-2026-2808
OESA-2026-2809
OESA-2026-2810
OPENSUSE-SU-2026:11161-1
OPENSUSE-SU-2026:21400-1
SUSE-SU-2026:22836-1
SUSE-SU-2026:3055-1

Affected Products

Radvd