PT-2026-82548 · Wicked · Wicked
CVSS v3.1
5.4
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
wicked versions prior to 0.6.81
Description
An out-of-bounds read exists in the DHCPv4 packet capture code. The function
ni capture inspect udp header() in src/capture.c incorrectly reports the IP total length as the payload length instead of the remaining UDP payload length. This causes the DHCP option walker in the DHCPv4 client (wickedd-dhcp4) to read up to 68 bytes beyond the end of the 1500-byte packet receive buffer. An unauthenticated attacker on the same network can send a crafted DHCP/UDP packet to force the client to parse adjacent heap memory as DHCP options, potentially allowing heap contents like allocator metadata or pointer values to be interpreted as lease fields.Recommendations
Update wicked to a version later than 0.6.80.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wicked