Logo
vulnerabilityCVE-2026-56116
Name
CVE-2026-56116
Source
NVD ( link)Debian ( link)
Description
dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dhcpcd
Exploitable

Vulnerability Ratings#


7.1
CVSSv4
6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
10.1.0
Exploitable
buildroot
master
10.2.4
Exploitable
yocto
kirkstone
9.4.1
Exploitable
yocto
master
10.5.2
Not Affected
yocto
scarthgap
10.0.6
Exploitable