PT-2026-48679 · Wicked · Wicked
CVE-2026-44932
·
Published
2026-06-10
·
Updated
2026-06-18
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wicked versions prior to 0.6.79
Description
An indirect remote shell command injection exists due to unsanitized DHCP options. The issue involves improper processing of
posix-tz-dbname and tz-string options, as well as a failure to escape single-quotes in leaseinfo dump output used by wicked test dhcp4 and wicked test dhcp6 and written to /run/wicked/leaseinfo.* files.Recommendations
Update to version 0.6.79.
Regenerate the initrd if it contains wicked binaries when updating from versions 0.6.78 and earlier.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wicked