CVE-2026-71401
published 2026-08-27CVE-2026-71401: An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c does not verify that the IP total…
PriorityP428medium5.3CVSS 4.0
AVAACLATNPRNUINVCNVINVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.18%
7.9th percentile
An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c does not verify that the IP total length field (ip_len) is at least as large as the IP header length (ihl) before subtracting the header length. An unauthenticated attacker on the same network can thereby trigger an out-of-bounds read past the receive buffer in the wicked DHCPv4 client (wickedd-dhcp4), which can crash the daemon depending on the process memory layout. No information disclosure has been demonstrated. This issue affects wicked up to and including version 0.6.80.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| suse | wicked | <= 0.6.80 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-71401 wicked: wicked: Denial of Service via integer underflow in DHCPv4 packet capture [fedora-all]
bugzilla·2026-09-01·CVSS 5.3
CVE-2026-71401 [MEDIUM] CVE-2026-71401 wicked: wicked: Denial of Service via integer underflow in DHCPv4 packet capture [fedora-all]
CVE-2026-71401 wicked: wicked: Denial of Service via integer underflow in DHCPv4 packet capture [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c does not verify that the IP total length field (ip_len) is at least as large as the IP header length (ihl) before subtracting the header length. An unauthenticated attacker on the same network can thereby trigger an out-of-bounds read past the receive buffer in the wicked DHCPv4 client (wickedd-dhcp4), which can crash the daemon depending
Bugzilla
CVE-2026-71401 wicked: wicked: Denial of Service via integer underflow in DHCPv4 packet capture
bugzilla·2026-08-27·CVSS 5.3
CVE-2026-71401 [MEDIUM] CVE-2026-71401 wicked: wicked: Denial of Service via integer underflow in DHCPv4 packet capture
CVE-2026-71401 wicked: wicked: Denial of Service via integer underflow in DHCPv4 packet capture
An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c does not verify that the IP total length field (ip_len) is at least as large as the IP header length (ihl) before subtracting the header length. An unauthenticated attacker on the same network can thereby trigger an out-of-bounds read past the receive buffer in the wicked DHCPv4 client (wickedd-dhcp4), which can crash the daemon depending on the process memory layout. No information disclosure has been demonstrated. This issue affects wicked up to and including version 0.6.80.
2026-08-27
Published