CVE-2026-56116

EUVD-2026-38496
dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 8.57%
Affected Products (NVD)
VendorProductVersion
dhcpcd_projectdhcpcd
𝑥
≤ 10.3.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dhcpcd
forky
1:10.3.2-6
fixed
sid
1:10.3.2-6
fixed
trixie
1:10.1.0-11+deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dhcpcd
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
dhcpcd
Azure Linux 3.0
0:10.0.8-2.azl3
fixed