PT-2026-49283 · Dhcpcd · Dhcpcd

CVE-2025-70102

·

Published

2025-06-15

·

Updated

2026-07-06

CVSS v3.1

6.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions dhcpcd version 10.3.0
Description A NULL pointer dereference occurs during the parsing of configuration options. In the parse option() function, the software performs a member access on a NULL pointer of type struct dhcp opt when an invalid option token or parsing state results in a NULL lookup.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10157
CVE-2025-70102
OPENSUSE-SU-2026:21220-1
SUSE-SU-2026:22542-1
SUSE-SU-2026:22561-1

Affected Products

Dhcpcd