CVE-2026-44932
published 2026-06-16CVE-2026-44932: Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server…
PriorityP350high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.36%
28.4th percentile
Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| suse | wicked | < 0.6.79 | 0.6.79 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.
ghsa_unreviewed·2026-06-16
CVE-2026-44932 [HIGH] CWE-78 Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.
Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.
VulDB
SUSE wicked up to 0.6.78 DHCP os command injection (Nessus ID 321062)
vuldb·2026-06-16·CVSS 8.8
CVE-2026-44932 [HIGH] SUSE wicked up to 0.6.78 DHCP os command injection (Nessus ID 321062)
A vulnerability marked as critical has been reported in SUSE wicked up to 0.6.78. Affected by this issue is some unknown functionality of the component DHCP Handler. Performing a manipulation results in os command injection.
This vulnerability is identified as CVE-2026-44932. The attack can only be performed from the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
Red Hat
wicked: wicked: Arbitrary code execution via unsanitized DHCP replies
vendor_redhat·2026-06-16·CVSS 8.8
CVE-2026-44932 [HIGH] CWE-94 wicked: wicked: Arbitrary code execution via unsanitized DHCP replies
wicked: wicked: Arbitrary code execution via unsanitized DHCP replies
Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.
A flaw was found in the wicked DHCP client. A remote attacker, by operating a malicious Dynamic Host Configuration Protocol (DHCP) server, could send specially crafted DHCP replies containing unsanitized strings. This vulnerability allows the attacker to execute arbitrary code on the local machine, potentially leading to a complete compromise of the affected system.
Statement: This Important vulnerability in the wicked DHCP client allows a remote attacker to achieve arbitrary code execution on a system configured to obtain a
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44932 wicked: wicked: Arbitrary code execution via unsanitized DHCP replies [fedora-all]
bugzilla·2026-06-22·CVSS 8.8
CVE-2026-44932 [HIGH] CVE-2026-44932 wicked: wicked: Arbitrary code execution via unsanitized DHCP replies [fedora-all]
CVE-2026-44932 wicked: wicked: Arbitrary code execution via unsanitized DHCP replies [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44932 wicked: wicked: Arbitrary code execution via unsanitized DHCP replies
bugzilla·2026-06-16·CVSS 8.8
CVE-2026-44932 [HIGH] CVE-2026-44932 wicked: wicked: Arbitrary code execution via unsanitized DHCP replies
CVE-2026-44932 wicked: wicked: Arbitrary code execution via unsanitized DHCP replies
Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.
https://bugzilla.suse.com/show_bug.cgi?id=1265221https://github.com/openSUSE/wicked/releases/tag/version-0.6.79https://lists.suse.com/pipermail/sle-security-updates/2026-June/026688.htmlhttps://lists.suse.com/pipermail/sle-security-updates/2026-June/026689.htmlhttps://lists.suse.com/pipermail/sle-security-updates/2026-June/026690.htmlhttps://lists.suse.com/pipermail/sle-security-updates/2026-June/026691.html
2026-06-16
Published