PT-2026-51563 · Dhcpcd · Dhcpcd
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
dhcpcd versions prior to 10.3.2
Description
A one-byte stack out-of-bounds write exists in the
dhcp6 makemessage() function within src/dhcp6.c. Unauthenticated attackers on the same link can trigger this by serializing an oversized RFC6603 OPTION PD EXCLUDE option body. This is achieved by sending a crafted DHCPv6 ADVERTISE message containing an IA PD IAPREFIX /0 with a valid OPTION PD EXCLUDE using an exclude prefix length between /121 and /128, which allows writing beyond a fixed local buffer and potentially corrupting adjacent stack memory.Recommendations
Update to the version containing commit 2f00c7b.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dhcpcd