PT-2026-51565 · Dhcpcd · Dhcpcd

·

CVE-2026-56116

·

Published

2026-06-23

·

Updated

2026-08-30

CVSS v4.0

7.1

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions dhcpcd versions prior to 10.3.2
Description An issue in the IPv6 Router Advertisement route information handling allows an unauthenticated attacker on the same link to cause a denial of service. By repeatedly sending crafted Router Advertisements containing Route Information options with a lifetime of zero, an attacker can trigger unfreed allocations in the routeinfo findalloc() function. This leads to linear memory exhaustion and an eventual crash of the daemon.
Recommendations Update to the version containing commit 708b4a5.

Exploit

Fix

DoS

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90219
CVE-2026-56116
OPENSUSE-SU-2026:11473-1
OPENSUSE-SU-2026:21692-1
SUSE-SU-2026:23400-1

Affected Products

Dhcpcd