A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Advertisement containing a zero-length Neighbor Discovery option can bypass validation during packet storage and later be reparsed without adequate validation, causing the parser to enter a non-advancing loop. Successful exploitation may result in excessive CPU consumption, leading to a denial of service.
References
Configurations
No configuration.
History
01 Jul 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/NetworkConfiguration/dhcpcd/issues/415 - |
01 Jul 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-01 11:16
Updated : 2026-07-01 18:31
NVD link : CVE-2026-14258
Mitre link : CVE-2026-14258
CVE.ORG link : CVE-2026-14258
JSON object : View
Products Affected
No product.
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
