Search CVE reports


Toggle filters

1 – 10 of 95 results


CVE-2026-56117

Medium priority
Needs evaluation

dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged attackers to trigger memory corruption when privilege...

1 affected package

dhcpcd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-56116

Medium priority
Needs evaluation

dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by...

1 affected package

dhcpcd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-56115

Medium priority
Needs evaluation

dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer...

1 affected package

dhcpcd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-56114

Medium priority
Needs evaluation

dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer...

1 affected package

dhcpcd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-56113

Medium priority
Needs evaluation

dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW reply with RFC6603...

1 affected package

dhcpcd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2025-70102

Medium priority
Needs evaluation

A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if-options.c:1886), the code performs a member access on a NULL pointer of type...

1 affected package

dhcpcd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-5950

Medium priority

Some fixes available 4 of 14

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific...

3 affected packages

bind9, bind9-libs, isc-dhcp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Fixed Fixed Needs evaluation Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
Show less packages

CVE-2026-5947

Medium priority
Fixed

Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. If, during that validation, the...

3 affected packages

bind9-libs, bind9, isc-dhcp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9-libs Not in release Not in release Not affected Not affected
bind9 Fixed Not affected Not affected Not affected Not affected
isc-dhcp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-5946

Medium priority

Some fixes available 4 of 10

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the...

3 affected packages

bind9-libs, bind9, isc-dhcp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9-libs Not in release Not in release Vulnerable Vulnerable
bind9 Fixed Fixed Fixed Needs evaluation Needs evaluation
isc-dhcp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-3593

Medium priority
Fixed

A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.0 through...

3 affected packages

bind9-libs, bind9, isc-dhcp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9-libs Not in release Not in release Not affected Not affected
bind9 Fixed Not affected Not affected Not affected Not affected
isc-dhcp Not affected Not affected Not affected Not affected Not affected
Show less packages