Junglewise Threat Intelligence

CVE-2026-56116: NetworkConfiguration dhcpcd memory leak in IPv6 Router Advertisement handling

CVE-2026-56116 · Severity: medium · CVSS 6.5 · Published 2026-06-23

Technologies: NetworkConfiguration Dhcpcd.

Executive brief

A memory leak vulnerability exists in dhcpcd, a widely used tool for managing network addresses on Linux and BSD systems. An attacker on the same local network can send specially crafted IPv6 messages that cause the software to consume all available system memory. This leads to a crash of the networking service, potentially disconnecting the device from the network and disrupting operations.

Technical details

A memory leak (CWE-401) exists in the IPv6 Router Advertisement (RA) route information handling of dhcpcd. The vulnerability is located in the routeinfo_findalloc() function within src/ipv6nd.c. An unauthenticated attacker on the same local link can send crafted RA packets containing Route Information options with a lifetime of zero. These packets trigger memory allocations that are not properly freed, leading to linear memory exhaustion. Repeated exploitation results in a daemon crash and denial of service. The issue is fixed in commit 708b4a5 by ensuring rinfo is freed when it expires.

Affected products

  • NetworkConfiguration dhcpcd through 10.3.2

Timeline

  • 2026-06-23: disclosed
  • 2026-06-23: advisory
  • 2026-06-23: patched: Fixed in commit 708b4a56bae080a5b18c2e0c4c6fbe103131a2b0

References