Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56116

Опубликовано: 23 июн. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dhcpcd_project:dhcpcd:*:*:*:*:*:*:*:*
Версия до 10.3.2 (включая)

EPSS

Процентиль: 9%
0.00188
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-401

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash.

CVSS3: 6.5
redhat
около 1 месяца назад

dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash.

CVSS3: 6.5
msrc
27 дней назад

dhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling

CVSS3: 6.5
debian
около 1 месяца назад

dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak ...

CVSS3: 6.5
github
около 1 месяца назад

dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash.

EPSS

Процентиль: 9%
0.00188
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-401