Executive brief
A vulnerability exists in dhcpcd, a widely used tool for managing network addresses on Linux and BSD systems. An attacker on the same local network can send a specially crafted network message to crash the service or potentially interfere with the system's memory. This could lead to a loss of network connectivity for the affected device.
Technical details
A one-byte stack-based out-of-bounds write exists in src/dhcp6.c within the dhcp6_makemessage() function. The root cause is an off-by-one error where a fixed 16-byte local buffer (exb) is used to serialize an RFC6603 OPTION_PD_EXCLUDE option body that can reach 17 bytes. An unauthenticated attacker on the same network link can trigger this by sending a crafted DHCPv6 ADVERTISE message containing an IA_PD IAPREFIX /0 with an exclude prefix length between /121 and /128. This allows the attacker to write one byte beyond the buffer, potentially corrupting adjacent stack memory and causing a crash. The issue is fixed in commit 2f00c7b by increasing the buffer size to 17 bytes.
Affected products
- NetworkConfiguration dhcpcd through 10.3.2
Timeline
- 2026-06-23: disclosed
- 2026-06-23: advisory