Logo
vulnerabilityCVE-2026-56113
Name
CVE-2026-56113
Source
NVD ( link)Debian ( link)
Description
dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW reply with RFC6603 OPTION_PD_EXCLUDE and both preferred and valid lifetimes set to zero. Attackers acting as or impersonating a DHCPv6 server can trigger dhcp6_deprecatedele() to free a delegated child address while an outer TAILQ_FOREACH_SAFE iterator in dhcp6_deprecateaddrs() still holds the freed pointer, causing a use-after-free when TAILQ_REMOVE is reached.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dhcpcd
Exploitable

Vulnerability Ratings#


6
CVSSv4
5.3
CVSSv31
6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
10.1.0
Exploitable
openwrt
master
10.0.10-r2
Exploitable
yocto
kirkstone
9.4.1
Exploitable
yocto
master
10.5.2
Not Affected
yocto
scarthgap
10.0.6
Exploitable