Dhcpcd
This hub aggregates every CVE we track for Dhcpcd, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
23
CVEs tracked
3
Critical
8
High
0
In CISA KEV
Severity distribution
MEDIUM11HIGH8CRITICAL3LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
4
0
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Dhcpcd.
- CVE-2026-56117dhcpcd Heap Use-After-Free via Control Socket Handling4.7
- CVE-2026-56116dhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling6.5
- CVE-2026-56114dhcpcd Stack Out-of-Bounds Write in dhcp6_makemessage()5.3
- CVE-2026-56113dhcpcd Heap Use-After-Free in dhcp6_deprecateaddrs via DHCPv6 RENEW5.3
- CVE-2021-25217A buffer overrun in lease file parsing code can be used to exploit a common vulnerability shared by dhcpd and dhclient7.4
- CVE-2019-6470dhcpd: use-after-free error leads crash in IPv6 mode when using mismatched BIND libraries6.5
- CVE-2019-11766dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.9.8
- CVE-2019-11579dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.5.3
- CVE-2019-11578auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks.5.9
- CVE-2019-11577dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses.9.8
- CVE-2018-5733A malicious client can overflow a reference counter in ISC dhcpd7.5
- CVE-2016-1504dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length.7.5
- CVE-2016-1503dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attac...9.8
- CVE-2012-6698The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted response.7.5
- CVE-2012-6700The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response.7.5
Product normalization is registry-driven with AI assist and human review. How it works