Integer Underflow in Wicked DHCPv4 Client Affects Network Security
CVE-2026-71401

5.3MEDIUM

Key Information:

Vendor

Suse

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-71401?

An integer underflow vulnerability has been identified in the DHCPv4 packet capture code of the Wicked DHCP client. The issue arises within the function ni_capture_inspect_udp_header() where the IP total length field is not adequately checked against the IP header length. This oversight allows an unauthenticated attacker on the same network to potentially manipulate network traffic, resulting in an out-of-bounds read past the receive buffer. Such exploitation could lead to instability in the wicked DHCPv4 client (wickedd-dhcp4), possibly causing the daemon to crash based on the process's memory layout. Currently, no data disclosure risks have been associated with this vulnerability. Users are urged to review their versions and consider updates to mitigate potential attacks.

Affected Version(s)

wicked 0 <= 0.6.80

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Birtwhistle
.