Threats Tagged 'cve-2026-56117'
View all threats tagged with 'cve-2026-56117'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-56117'
Click on any threat for detailed analysis and mitigation recommendations
0 Multiple security vulnerabilities were fixed in dhcpcd version 10.5.0. These include denial of service via crafted DHCPv6 RENEW replies, a one-byte stack out-of-bounds write from DHCPv6 ADVERTISE messages, a memory leak from Router Advertisements with zero lifetime Route Information options, and a heap use-after-free triggered by crafted privileged commands over writable control sockets. The update also includes numerous code improvements and bug fixes. Join the discussion | GCVE Database | 08/30/2026, 14:33:19 UTC Added: 09/17/2026, 01:58:54 UTC |
dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW reply with RFC6603 OPTION_PD_EXCLUDE and both preferred and valid lifetimes set to zero. Attackers acting as or impersonating a DHCPv6 server can trigger dhcp6_deprecatedele() to free a delegated child address while an outer TAILQ_FOREACH_SAFE iterator in dhcp6_deprecateaddrs() still holds the freed pointer, causing a use-after-free when TAILQ_REMOVE is reached. Join the discussion | CVE Database V5 | 08/09/2026, 00:00:00 UTC Added: 06/23/2026, 16:39:54 UTC |
dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged attackers to trigger memory corruption when privilege separation is disabled. Attackers can connect to the control socket and send a privileged command such as -x, causing control_recvdata() to free the client object while the same READ+HANGUP event subsequently reaches control_hangup() with the stale pointer, resulting in a use-after-free condition exploitable in deployments using --disable-privsep or where privsep initialization has failed with the control socket operating in mode 0666. Join the discussion | CVE Database V5 | 06/23/2026, 16:14:31 UTC Added: 06/23/2026, 16:39:55 UTC |
Showing 1 to 3 of 3 results