RHSA-2026:54210: Moderate: dhcpcd security update
Moderate: dhcpcd security update
Other sources
The dhcpcd package provides a minimalistic network configuration daemon that supports IPv4 and IPv6 configuration including configuration discovery through NDP, DHCPv4 and DHCPv6 protocols.Security Fix(es): dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length IPv6 ND option in Router Advertisement handling (CVE-2026-14258) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/dhcpcdto a version that resolves this vulnerability.Fixed in 10.0.6-11.el10_2 - Upgrade
Upgrade
redhat/dhcpcd-debuginfoto a version that resolves this vulnerability.Fixed in 10.0.6-11.el10_2 - Upgrade
Upgrade
redhat/dhcpcd-debugsourceto a version that resolves this vulnerability.Fixed in 10.0.6-11.el10_2 - Upgrade
Upgrade
redhat/dhcpcdto a version that resolves this vulnerability.Fixed in 10.0.6-11.el10_2.aa - Upgrade
Upgrade
redhat/dhcpcd-debuginfoto a version that resolves this vulnerability.Fixed in 10.0.6-11.el10_2.aa - Upgrade
Upgrade
redhat/dhcpcd-debugsourceto a version that resolves this vulnerability.Fixed in 10.0.6-11.el10_2.aa - Upgrade
Upgrade
dhcpcdto a version that resolves this vulnerability.Patch CVE-2026-14258
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54210?
The severity of RHSA-2026:54210 is classified as medium with a score of 4.
What vulnerabilities does RHSA-2026:54210 address?
RHSA-2026:54210 addresses an infinite loop and an out-of-bounds read in the dhcpcd package.
How do I fix RHSA-2026:54210?
To fix RHSA-2026:54210, update the dhcpcd package to the latest version provided by Red Hat.
Which software packages are affected by RHSA-2026:54210?
The affected software packages include redhat/dhcpcd and its associated debug and debug source packages.
When was RHSA-2026:54210 published?
RHSA-2026:54210 was published on August 12, 2026.