PT-2026-82547 · Wicked · Wicked
CVSS v4.0
5.3
Medium
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
wicked versions prior to 0.6.81
Description
An integer underflow exists in the DHCPv4 packet capture code of the
wickedd-dhcp4 client. The function ni capture inspect udp header() in src/capture.c fails to verify that the IP total length field ip len is at least as large as the IP header length ihl before performing subtraction. An unauthenticated attacker on the same network can exploit this to trigger an out-of-bounds read past the receive buffer, potentially causing the daemon to crash depending on the process memory layout.Recommendations
Update wicked to a version later than 0.6.80.
Exploit
Fix
Integer Underflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wicked