← Back

CVE-2026-42512

nvd nist
Published: Apr 30, 2026Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrectly calculates its new size when requesting memory, resulting in a heap buffer overrun. A specially crafted packet can cause dhclient to overrun its buffer of environment entries. This can result in a crash, but it may be possible to leverage this bug to achieve remote code execution.

Affected (37)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
37 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 13.5
Version 13.5 beta3
Version 13.5 p10
Version 13.5 p11
Version 13.5 p12
Version 13.5 p1
Version 13.5 p2
Version 13.5 p3
Version 13.5 p4
Version 13.5 p5
Version 13.5 p6
Version 13.5 p7
Version 13.5 p8
Version 13.5 p9
Version 14.3
Version 14.3 p10
Version 14.3 p11
Version 14.3 p1
Version 14.3 p2
Version 14.3 p3
Version 14.3 p4
Version 14.3 p5
Version 14.3 p6
Version 14.3 p7
Version 14.3 p8
Version 14.3 p9
Version 14.4
Version 14.4 p1
Version 14.4 p2
Version 14.4 rc1
Version 15.0
Version 15.0 p1
Version 15.0 p2
Version 15.0 p3
Version 15.0 p4
Version 15.0 p5
Version 15.0 p6

References (1)

Timeline

No history available yet.