dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "8.0"
},
{
"last_affected": "8.0"
},
{
"introduced": "9.0"
},
{
"last_affected": "9.0"
},
{
"introduced": "10.0"
},
{
"last_affected": "10.0"
}
],
"source": "CPE_STRING",
"vendor_product": "debian:debian_linux"
}
]
}{
"cpe": "cpe:2.3:a:dhcpcd_project:dhcpcd:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "6.11.7"
},
{
"introduced": "7.0.0"
},
{
"fixed": "7.2.2"
}
],
"source": "CPE_RANGE"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11766.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "129949654370244262757538485416123606766",
"length": 3042
},
"id": "CVE-2019-11766-e16b9d3d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/NetworkConfiguration/dhcpcd/commit/d30538898e39cc9a49ced4e67e91013d1d84a2c2",
"target": {
"file": "src/dhcp6.c",
"function": "dhcp6_findpd"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"128791362724316076833846390335608624616",
"276512548865701510008981561576257645523",
"164597777333323718200872289213334073819",
"37736796150810945481206810595216785099",
"43626031906383246725332989478497325814",
"12939491439161782283134484832739147034",
"56198155499831416563622155107367737444",
"278973541740820641167815533192217982337",
"231857893143996889906446267693147760429"
],
"threshold": 0.9
},
"id": "CVE-2019-11766-e35b638e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/NetworkConfiguration/dhcpcd/commit/d30538898e39cc9a49ced4e67e91013d1d84a2c2",
"target": {
"file": "src/dhcp6.c"
}
}
]
"2026-08-27T08:14:23Z"
{
"cpe": "cpe:2.3:a:dhcpcd_project:dhcpcd:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "6.11.7"
},
{
"introduced": "7.0.0"
},
{
"fixed": "7.2.2"
}
],
"source": "CPE_RANGE"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11766.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"128791362724316076833846390335608624616",
"276512548865701510008981561576257645523",
"164597777333323718200872289213334073819",
"37736796150810945481206810595216785099",
"43626031906383246725332989478497325814",
"12939491439161782283134484832739147034",
"56198155499831416563622155107367737444",
"278973541740820641167815533192217982337",
"231857893143996889906446267693147760429"
],
"threshold": 0.9
},
"id": "CVE-2019-11766-03ad4df6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/networkconfiguration/dhcpcd/commit/d30538898e39cc9a49ced4e67e91013d1d84a2c2",
"target": {
"file": "src/dhcp6.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "129949654370244262757538485416123606766",
"length": 3042
},
"id": "CVE-2019-11766-0a25a507",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/networkconfiguration/dhcpcd/commit/d30538898e39cc9a49ced4e67e91013d1d84a2c2",
"target": {
"file": "src/dhcp6.c",
"function": "dhcp6_findpd"
}
}
]
"2026-08-27T08:14:23Z"