CVE-2026-56116
MEDIUMdhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling
Title source: cnaDescription
dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash.
References (2)
Core 2
Core References
Patch patch
https://github.com/NetworkConfiguration/dhcpcd/commit/708b4a56bae080a5b18c2e0c4c6fbe103131a2b0
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/dhcpcd-memory-leak-dos-via-ipv6-router-advertisement-handling
Scores
CVSS v3
6.5
EPSS
0.0019
EPSS Percentile
8.6%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-401
Status
published
Products (2)
NetworkConfiguration/dhcpcd
< 10.3.2
NetworkConfiguration/dhcpcd
708b4a56bae080a5b18c2e0c4c6fbe103131a2b0
Published
Jun 23, 2026
Tracked Since
Jun 23, 2026