Out-of-Bounds Read Vulnerability in wicked DHCPv4 Client
CVE-2026-71402

5.3MEDIUM

Key Information:

Vendor

Suse

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-71402?

An issue exists in the wicked DHCPv4 client where an out-of-bounds read occurs during packet capture processing. Due to flawed handling in the ni_capture_inspect_udp_header function, the DHCP client miscalculates the payload length, allowing an attacker to read up to 68 bytes beyond the intended buffer. This can lead to the interpretation of sensitive data from adjacent heap memory as DHCP options if exploited. While the over-read is limited, it poses a potential risk of information leakage that could be manipulated for further attacks within the local network environment.

Affected Version(s)

wicked 0 <= 0.6.80

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Birtwhistle
.