PT-2026-82547 · Wicked · Wicked

·

CVE-2026-71401

·

Published

2026-08-27

·

Updated

2026-08-28

CVSS v4.0

5.3

Medium

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions wicked versions prior to 0.6.81
Description An integer underflow exists in the DHCPv4 packet capture code of the wickedd-dhcp4 client. The function ni capture inspect udp header() in src/capture.c fails to verify that the IP total length field ip len is at least as large as the IP header length ihl before performing subtraction. An unauthenticated attacker on the same network can exploit this to trigger an out-of-bounds read past the receive buffer, potentially causing the daemon to crash depending on the process memory layout.
Recommendations Update wicked to a version later than 0.6.80.

Exploit

Fix

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71401
OPENSUSE-SU-2026:11636-1
OPENSUSE-SU-2026:21669-1
SUSE-SU-2026:3837-1
SUSE-SU-2026:3839-1
SUSE-SU-2026:3840-1
SUSE-SU-2026:3841-1
SUSE-SU-2026:3842-1

Affected Products

Wicked