VYPR
Medium severityNVD Advisory· Published Aug 27, 2026

CVE-2026-71401

CVE-2026-71401

Description

An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c does not verify that the IP total length field (ip_len) is at least as large as the IP header length (ihl) before subtracting the header length. An unauthenticated attacker on the same network can thereby trigger an out-of-bounds read past the receive buffer in the wicked DHCPv4 client (wickedd-dhcp4), which can crash the daemon depending on the process memory layout. No information disclosure has been demonstrated. This issue affects wicked up to and including version 0.6.80.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • OpenSUSE/Wickedreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=0.6.80

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.