PT-2026-51565 · Networkconfiguration · Dhcpcd

Cub3Y0Nd

+1

·

Published

2026-06-23

·

Updated

2026-06-23

·

CVE-2026-56116

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo findalloc() that cause linear memory exhaustion and eventual daemon crash.

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56116

Affected Products

Dhcpcd