VYPR

rpm package

opensuse/dhcpcd&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/dhcpcd&distro=openSUSE%20Leap%2016.0

Vulnerabilities (5)

  • CVE-2026-56117MedJun 23, 2026
    affected < 10.5.0-160000.1.1fixed 10.5.0-160000.1.1

    dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged attackers to trigger memory corruption when privilege separation is disabled. Attackers can connect to t

  • CVE-2026-56116MedJun 23, 2026
    affected < 10.5.0-160000.1.1fixed 10.5.0-160000.1.1

    dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can re

  • CVE-2026-56115HigJun 23, 2026
    affected < 10.5.0-160000.1.1fixed 10.5.0-160000.1.1

    Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to perform administrative actions by exploiting missing role enforcement in the JWTMiddleware function in internal/auth/auth.go, which validates JWT tokens and ac

  • CVE-2026-56113MedJun 23, 2026
    affected < 10.5.0-160000.1.1fixed 10.5.0-160000.1.1

    dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW reply with RFC6603 OPTION_PD_EXCLUDE and both preferred and valid lifetimes set to ze

  • CVE-2025-70102MedJun 15, 2026
    affected < 10.3.2-160000.1.2fixed 10.3.2-160000.1.2

    A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if-options.c:1886), the code performs a member access on a NULL pointer of type 'struct dhcp_opt' when an unexpected/invalid option toke