CVE-2026-56116

MEDIUM

dhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling

Title source: cna
STIX 2.1

Description

dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash.

Scores

CVSS v3 6.5
EPSS 0.0019
EPSS Percentile 8.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (2)
NetworkConfiguration/dhcpcd < 10.3.2
NetworkConfiguration/dhcpcd 708b4a56bae080a5b18c2e0c4c6fbe103131a2b0
Published Jun 23, 2026
Tracked Since Jun 23, 2026