Updated dhcpcd packages fix security vulnerabilities
Publication date: 13 Aug 2026Modification date: 13 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56114 , CVE-2026-56116
Description
Attackers can send a crafted DHCPv6 ADVERTISE message containing an
IA_PD
IAPREFIX /0 with a valid OPTION_PD_EXCLUDE using an exclude prefix
length
of /121 through /128 to trigger the out-of-bounds write and potentially
corrupt adjacent stack memory (CVE: CVE-2026-56114).
Attackers can repeatedly send Router Advertisements containing Route
Information options with a lifetime of zero, triggering unfreed
allocations in routeinfo_findalloc() that cause linear memory
exhaustion and eventual daemon crash (CVE: CVE-2026-56116).
References
SRPMS
10/core
- dhcpcd-10.5.0-1.1.mga10