Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90213.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-90213
Upstream
Published
2026-06-23T17:17:09Z
Modified
2026-08-29T05:27:27Z
Summary
CVE-2026-56113 affecting package dhcpcd for versions less than 10.0.8-4
Details

dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW reply with RFC6603 OPTIONPDEXCLUDE and both preferred and valid lifetimes set to zero. Attackers acting as or impersonating a DHCPv6 server can trigger dhcp6deprecatedele() to free a delegated child address while an outer TAILQFOREACHSAFE iterator in dhcp6deprecateaddrs() still holds the freed pointer, causing a use-after-free when TAILQ_REMOVE is reached.

References

Affected packages

Azure Linux:3 / dhcpcd

Package

Name
dhcpcd
Purl
pkg:rpm/azure-linux/dhcpcd

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.8-4

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90213.json"