Out-of-Bounds Read Vulnerability in wicked DHCPv4 Client
CVE-2026-71402
5.3MEDIUM
What is CVE-2026-71402?
An issue exists in the wicked DHCPv4 client where an out-of-bounds read occurs during packet capture processing. Due to flawed handling in the ni_capture_inspect_udp_header function, the DHCP client miscalculates the payload length, allowing an attacker to read up to 68 bytes beyond the intended buffer. This can lead to the interpretation of sensitive data from adjacent heap memory as DHCP options if exploited. While the over-read is limited, it poses a potential risk of information leakage that could be manipulated for further attacks within the local network environment.
Affected Version(s)
wicked 0 <= 0.6.80