CVE-2026-48715

EUVD-2026-38070
radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, `print_ff()` copies up to 2032 bytes from attacker-controlled packet data into a 16-byte `struct in6_addr` on the stack, overflowing by up to 2016 bytes. Note that the main `radvd` daemon is not affected by the vulnerability. Version 2.21 patches the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Affected Products (NVD)
VendorProductVersion
radvd.litechradvd
𝑥
< 2.21
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
radvd
bookworm
unimportant
bullseye
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
radvd
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
radvd
Amazon Linux 2023
0:2.19-2.amzn2023.0.3
fixed
radvd-debuginfo
Amazon Linux 2023
0:2.19-2.amzn2023.0.3
fixed
radvd-debugsource
Amazon Linux 2023
0:2.19-2.amzn2023.0.3
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
radvd
Azure Linux 3.0
0:2.21-1.azl3
fixed