Heap Buffer Overrun in dhclient Affects FreeBSD
CVE-2026-42512
Currently unrated
What is CVE-2026-42512?
The vulnerability in dhclient occurs when the program attempts to resize an array of string pointers. An error in the code that calculates the new size required for memory can lead to a heap buffer overrun. When a specially crafted packet is received, this flaw may cause dhclient to overrun its buffer of environment entries, potentially leading to crashes. There is also a risk that this bug could be exploited to achieve remote code execution, presenting a significant security threat.
Affected Version(s)
FreeBSD 15.0-RELEASE
FreeBSD 14.4-RELEASE
FreeBSD 14.3-RELEASE
