CVE-2026-48715

EUVD-2026-38070
radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, `print_ff()` copies up to 2032 bytes from attacker-controlled packet data into a 16-byte `struct in6_addr` on the stack, overflowing by up to 2016 bytes. Note that the main `radvd` daemon is not affected by the vulnerability. Version 2.21 patches the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 10.56%
Affected Products (NVD)
VendorProductVersion
radvd.litechradvd
𝑥
< 2.21
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
radvd
bookworm
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
radvd
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
radvd
Amazon Linux 2023
0:2.19-2.amzn2023.0.3
fixed
radvd-debuginfo
Amazon Linux 2023
0:2.19-2.amzn2023.0.3
fixed
radvd-debugsource
Amazon Linux 2023
0:2.19-2.amzn2023.0.3
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
radvd
Azure Linux 3.0
0:2.21-1.azl3
fixed