Junglewise Threat Intelligence

CVE-2026-56117: NetworkConfiguration dhcpcd heap use-after-free in control socket handling

CVE-2026-56117 · Severity: medium · CVSS 4.7 · Published 2026-06-23

Technologies: NetworkConfiguration Dhcpcd.

Executive brief

A vulnerability exists in dhcpcd, a common tool used by Linux and BSD systems to configure network interfaces. A local user could potentially crash the networking service or cause system instability by sending specific commands to the tool's internal communication channel. This issue primarily affects systems where certain security isolation features (privilege separation) are disabled or fail to initialize.

Technical details

A heap use-after-free vulnerability exists in src/control.c of dhcpcd through version 10.3.2. The flaw is triggered when an attacker connects to the control socket and sends a privileged command (e.g., -x). This causes control_recvdata() to free a client object, but a subsequent READ+HANGUP event reaches control_hangup() which still holds a stale pointer to that same object. This condition is exploitable in environments where privilege separation is explicitly disabled via --disable-privsep or where it fails to initialize, leaving the control socket in mode 0666. The issue has been addressed in commit 78ea09e by ensuring errors are bubbled up so objects are freed more cleanly.

Affected products

  • NetworkConfiguration dhcpcd through 10.3.2

Timeline

  • 2026-06-23: disclosed
  • 2026-06-23: advisory
  • 2026-06-23: patched: Fixed in commit 78ea09e

References