cbcvebase.

Suse Wicked vulnerabilities

3 known vulnerabilities affecting suse/wicked.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-44932P3HIGHCVSS 8.8fixed in 0.6.792026-06-16
CVE-2026-44932 [HIGH] CWE-78 CVE-2026-44932: Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 co Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.
nvd
CVE-2026-71402P4MEDIUMCVSS 5.4≤ 0.6.802026-08-27
CVE-2026-71402 [MEDIUM] CWE-125 CVE-2026-71402: An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_ An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c reports the IP total length as the payload length instead of the length of the remaining UDP payload. Consequently, the DHCP option walker in the DHCPv4 client (wickedd-dhcp4) reads up to ihl + 8 bytes — at most 68 bytes — pa
nvd
CVE-2026-71401P4MEDIUMCVSS 5.3≤ 0.6.802026-08-27
CVE-2026-71401 [MEDIUM] CWE-191 CVE-2026-71401: An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_h An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c does not verify that the IP total length field (ip_len) is at least as large as the IP header length (ihl) before subtracting the header length. An unauthenticated attacker on the same network can thereby trigger an out-of-bou
nvd
Suse Wicked vulnerabilities | cvebase