PT-2026-51565 · Dhcpcd · Dhcpcd
CVSS v4.0
7.1
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
dhcpcd versions prior to 10.3.2
Description
An issue in the IPv6 Router Advertisement route information handling allows an unauthenticated attacker on the same link to cause a denial of service. By repeatedly sending crafted Router Advertisements containing Route Information options with a lifetime of zero, an attacker can trigger unfreed allocations in the
routeinfo findalloc() function. This leads to linear memory exhaustion and an eventual crash of the daemon.Recommendations
Update to the version containing commit 708b4a5.
Exploit
Fix
DoS
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dhcpcd