MGASA-2026-0335

Source
https://advisories.mageia.org/MGASA-2026-0335.html
Import Source
https://advisories.mageia.org/MGASA-2026-0335.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0335
Upstream
Published
2026-08-13T21:59:25Z
Modified
2026-08-13T22:00:03.705227515Z
Summary
Updated dhcpcd packages fix security vulnerabilities
Details

Attackers can send a crafted DHCPv6 ADVERTISE message containing an IAPD IAPREFIX /0 with a valid OPTIONPDEXCLUDE using an exclude prefix length of /121 through /128 to trigger the out-of-bounds write and potentially corrupt adjacent stack memory (CVE: CVE-2026-56114). Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfofindalloc() that cause linear memory exhaustion and eventual daemon crash (CVE: CVE-2026-56116).

References
Credits

Affected packages

Mageia:10 / dhcpcd

Package

Name
dhcpcd
Purl
pkg:rpm/mageia/dhcpcd?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.5.0-1.1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0335.json"