Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.1%top 99%

CVE-2026-56117: Use After Free in NetworkConfiguration dhcpcd

0
Medium
VulnerabilityCVE-2026-56117cvecve-2026-56117
Published: 06/23/2026 (06/23/2026, 16:14:31 UTC)
Source: CVE Database V5
Vendor/Project: NetworkConfiguration
Product: dhcpcd

Description

dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged attackers to trigger memory corruption when privilege separation is disabled. Attackers can connect to the control socket and send a privileged command such as -x, causing control_recvdata() to free the client object while the same READ+HANGUP event subsequently reaches control_hangup() with the stale pointer, resulting in a use-after-free condition exploitable in deployments using --disable-privsep or where privsep initialization has failed with the control socket operating in mode 0666.

CVSS v4.0

Score 5.7medium

Attack Vector
Local
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected software

GitHub Actionsmore threats →cve
dhcpcd
pkg:github/dhcpcd
Affected versions
<=10.3.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 00:46:43 UTC

Technical Analysis

The dhcpcd daemon versions up to and including 10.3.2 contain a heap use-after-free vulnerability in src/control.c related to control socket handling. When privilege separation is disabled or fails, an attacker with local access can connect to the control socket and send privileged commands (e.g., -x). This triggers control_recvdata() to free the client object, but a subsequent READ+HANGUP event causes control_hangup() to access the now-freed client pointer, resulting in a use-after-free condition. This vulnerability can lead to memory corruption under these specific conditions. The issue is resolved in commit 78ea09e.

Potential Impact

Local unprivileged attackers can exploit this vulnerability to cause memory corruption in dhcpcd when privilege separation is disabled or not properly initialized. This may lead to instability or potential escalation scenarios depending on the deployment. The vulnerability does not affect configurations where privilege separation is enabled and functioning correctly.

Mitigation Recommendations

A fix is available in the dhcpcd source code as of commit 78ea09e. Users should upgrade to a version including this commit or later. Until patched, ensure that privilege separation is enabled and properly initialized to mitigate the risk. No official vendor advisory or patch link is provided, so users should monitor the dhcpcd project for official releases containing this fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-06-18T19:15:10.651Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null

Threat ID: 6a3ab6dbeed863c81e4f9f6c

Added to database: 06/23/2026, 16:39:55 UTC

Last enriched: 07/30/2026, 00:46:43 UTC

Last updated: 08/06/2026, 12:41:11 UTC

Views: 59

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses