CVE-2026-56114

EUVD-2026-38492
dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer by serializing an oversized RFC6603 OPTION_PD_EXCLUDE option body. Attackers can send a crafted DHCPv6 ADVERTISE message containing an IA_PD IAPREFIX /0 with a valid OPTION_PD_EXCLUDE using an exclude prefix length of /121 through /128 to trigger the out-of-bounds write and potentially corrupt adjacent stack memory.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 7.21%
Affected Products (NVD)
VendorProductVersion
dhcpcd_projectdhcpcd
𝑥
≤ 10.3.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dhcpcd
forky
1:10.3.2-6
fixed
sid
1:10.3.2-6
fixed
trixie
1:10.1.0-11+deb13u3
fixed
dhcpcd5
bookworm
9.4.1-24~deb12u5
fixed
bullseye
vulnerable
bullseye (security)
7.1.0-2+deb11u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dhcpcd
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
dhcpcd
Azure Linux 3.0
0:10.0.8-2.azl3
fixed