dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-401"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56116.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "10.3.2"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:dhcpcd_project:dhcpcd:*:*:*:*:*:*:*:*"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-56116.json"
[
{
"target": {
"function": "ipv6nd_expirera",
"file": "src/ipv6nd.c"
},
"deprecated": false,
"source": "https://github.com/networkconfiguration/dhcpcd/commit/708b4a56bae080a5b18c2e0c4c6fbe103131a2b0",
"id": "CVE-2026-56116-229095a6",
"signature_version": "v1",
"digest": {
"length": 3337.0,
"function_hash": "147220208220241771676475277637298184653"
},
"signature_type": "Function"
},
{
"target": {
"file": "src/ipv6nd.c"
},
"deprecated": false,
"source": "https://github.com/networkconfiguration/dhcpcd/commit/708b4a56bae080a5b18c2e0c4c6fbe103131a2b0",
"id": "CVE-2026-56116-2852a25f",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"126462191768933859182625905064871798288",
"84695921800275119134825809965024024465",
"312500445576796603602710037254256645037",
"199358609586216563177532641102698207107"
]
},
"signature_type": "Line"
}
]
"2026-08-12T16:41:25Z"