CVE-2026-56116: dhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling
dhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling
Other sources
dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfofindalloc() that cause linear memory exhaustion and eventual daemon crash.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.8-2 - Upgrade
Upgrade
dhcpcdto a version that resolves this vulnerability.Fixed in 10.3.2Patch 708b4a5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56116?
The severity of CVE-2026-56116 is classified as high with a score of 7.1.
How do I fix CVE-2026-56116?
CVE-2026-56116 can be fixed by updating dhcpcd to the version that includes commit 708b4a5.
What are the potential impacts of CVE-2026-56116?
The potential impact of CVE-2026-56116 is a denial of service caused by a memory leak when handling IPv6 Router Advertisements.
Who can exploit CVE-2026-56116?
CVE-2026-56116 can be exploited by an unauthenticated same-link attacker.
What software is affected by CVE-2026-56116?
The software affected by CVE-2026-56116 is dhcpcd versions through 10.3.2.