High severity8.8NVD Advisory· Published Jun 19, 2026· Updated Jun 26, 2026
CVE-2026-48715
CVE-2026-48715
Description
radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the radvdump utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, print_ff() copies up to 2032 bytes from attacker-controlled packet data into a 16-byte struct in6_addr on the stack, overflowing by up to 2016 bytes. Note that the main radvd daemon is not affected by the vulnerability. Version 2.21 patches the issue.
Affected products
2- osv-coords2 versionspkg:rpm/opensuse/radvd&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/radvd&distro=openSUSE%20Tumbleweed
< 2.21-160000.1.1+ 1 more
- (no CPE)range: < 2.21-160000.1.1
- (no CPE)range: < 2.21-1.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.