CVE-2026-44932

EUVD-2026-37127
Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
wicked
suse enterprise desktop 15 SP7
0.6.79-150700.3.3.1
fixed
suse enterprise sap 15 SP7
0.6.79-150700.3.3.1
fixed
suse enterprise server 12 SP3
0.6.79-38.86.1
fixed
suse enterprise server 12 SP5
0.6.79-3.56.1
fixed
suse enterprise server 15 SP4
0.6.79-150400.3.39.1
fixed
suse enterprise server 15 SP5
0.6.79-150500.3.42.1
fixed
suse enterprise server 15 SP7
0.6.79-150700.3.3.1
fixed
wicked-nbft
suse enterprise desktop 15 SP7
0.6.79-150700.3.3.1
fixed
suse enterprise sap 15 SP7
0.6.79-150700.3.3.1
fixed
suse enterprise server 15 SP5
0.6.79-150500.3.42.1
fixed
suse enterprise server 15 SP7
0.6.79-150700.3.3.1
fixed
wicked-service
suse enterprise desktop 15 SP7
0.6.79-150700.3.3.1
fixed
suse enterprise sap 15 SP7
0.6.79-150700.3.3.1
fixed
suse enterprise server 12 SP3
0.6.79-38.86.1
fixed
suse enterprise server 12 SP5
0.6.79-3.56.1
fixed
suse enterprise server 15 SP4
0.6.79-150400.3.39.1
fixed
suse enterprise server 15 SP5
0.6.79-150500.3.42.1
fixed
suse enterprise server 15 SP7
0.6.79-150700.3.3.1
fixed