Junglewise Threat Intelligence

CVE-2026-44932: openSUSE wicked command injection via unsanitized DHCP options

CVE-2026-44932 · Severity: high · CVSS 8.8 · Published 2026-06-16

Technologies: Suse Linux Enterprise Server, Opensuse Wicked, Opensuse Leap. Vendors: Opensuse, Suse.

Executive brief

A vulnerability in the wicked network configuration tool, used in various SUSE and openSUSE Linux distributions, could allow an attacker to take control of a system. By operating a malicious DHCP server on the same local network, an attacker can send specially crafted network configuration data that triggers the execution of unauthorized commands. This could lead to a full system compromise, especially in environments using remote disk mounting or early-boot network services.

Technical details

A command injection vulnerability exists in the wicked DHCP client due to improper neutralization of special elements in DHCP options. When processing options like POSIXTZSTRING, the client writes unsanitized values into leaseinfo files (e.g., /run/wicked/leaseinfo.*) enclosed in single quotes but without escaping. If these files are subsequently sourced by shell scripts—such as those in dracut's network-legacy module or cloud-netconfig—an attacker on the adjacent network can achieve arbitrary code execution as root. The issue is fixed in wicked version 0.6.79 by implementing proper single-quote escaping and stricter character validation for specific RFC4833 options.

Affected products

  • openSUSE wicked before 0.6.79
  • SUSE SUSE Linux Enterprise Server 15 SP4, 15 SP5, 15 SP6
  • openSUSE openSUSE Leap 15.4, 15.5, 15.6

Timeline

  • 2026-05-13: disclosed: Vulnerability reported to SUSE by Wolfgang Frisch
  • 2026-06-10: patched: SUSE released security updates for SLE and Leap products
  • 2026-06-15: patched: wicked version 0.6.79 released on GitHub
  • 2026-06-16: advisory: CVE-2026-44932 published in NVD

References

Related threats