Infinite Loop Vulnerability in OpenBSD Daemons
CVE-2026-41285
4.3MEDIUM
What is CVE-2026-41285?
In OpenBSD versions up to 7.8, a vulnerability exists within the slaacd and rad daemons that leads to an infinite loop when they process a specifically crafted ICMPv6 Neighbor Discovery (ND) option containing a zero length. This occurs due to a flaw in the calculation handled within the code, specifically the expression that relies on the nd_opt_len variable without verifying if it is zero beforehand. As a result, an attacker located on the same local network could exploit this vulnerability, potentially leading to system resource exhaustion and service disruption.
Affected Version(s)
OpenBSD 0 <= 7.8