Advisories ยป MGASA-2026-0335

Updated dhcpcd packages fix security vulnerabilities

Publication date: 13 Aug 2026
Modification date: 13 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56114 , CVE-2026-56116

Description

Attackers can send a crafted DHCPv6 ADVERTISE message containing an
IA_PD
IAPREFIX /0 with a valid OPTION_PD_EXCLUDE using an exclude prefix
length
of /121 through /128 to trigger the out-of-bounds write and potentially
corrupt adjacent stack memory (CVE: CVE-2026-56114).
Attackers can repeatedly send Router Advertisements containing Route
Information options with a lifetime of zero, triggering unfreed
allocations in routeinfo_findalloc() that cause linear memory
exhaustion and eventual daemon crash (CVE: CVE-2026-56116).
                

References

SRPMS

10/core