Junglewise Threat Intelligence

CVE-2026-14258: NetworkConfiguration dhcpcd infinite loop in IPv6 Router Advertisement handling

CVE-2026-14258 · Severity: medium · CVSS 6.5 · Published 2026-07-01

Technologies: NetworkConfiguration Dhcpcd.

Executive brief

A vulnerability in the dhcpcd network configuration tool can allow an attacker on the same local network to crash the service or make it unresponsive. By sending a specially crafted network advertisement message, an attacker can force the software into an infinite loop that consumes excessive processor resources. This results in a denial of service, potentially disrupting network connectivity for the affected system.

Technical details

A vulnerability exists in dhcpcd's IPv6 Neighbor Discovery (ND) Router Advertisement (RA) processing within `src/ipv6nd.c`. While the initial handler (`ipv6nd_handlera`) identifies zero-length ND options, it fails to discard the malformed packet before it is stored. Subsequent re-parsing of the stored RA in functions such as `ipv6nd_env` and `ipv6nd_expirera` lacks adequate validation, causing the parser to enter a non-advancing loop when `nd_opt_len` is zero. An unauthenticated attacker on the same Layer 2 segment can exploit this by sending a crafted ICMPv6 RA, leading to high CPU consumption and a denial of service. A patch has been proposed to add explicit length validation in the re-parsing loops.

Affected products

  • NetworkConfiguration dhcpcd 10.0.6-10.el10

Timeline

  • 2024-12-01: disclosed: Issue first reported on GitHub
  • 2026-04-26: other: Bug reported to Red Hat Bugzilla
  • 2026-07-01: advisory: CVE published and NVD record created

References