CVE-2026-56113

EUVD-2026-38491
dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW reply with RFC6603 OPTION_PD_EXCLUDE and both preferred and valid lifetimes set to zero. Attackers acting as or impersonating a DHCPv6 server can trigger dhcp6_deprecatedele() to free a delegated child address while an outer TAILQ_FOREACH_SAFE iterator in dhcp6_deprecateaddrs() still holds the freed pointer, causing a use-after-free when TAILQ_REMOVE is reached.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 7.21%
Affected Products (NVD)
VendorProductVersion
dhcpcd_projectdhcpcd
𝑥
≤ 10.3.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dhcpcd
forky
1:10.3.2-6
fixed
sid
1:10.3.2-6
fixed
trixie
1:10.1.0-11+deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dhcpcd
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
dhcpcd
Azure Linux 3.0
0:10.0.8-4.azl3
fixed