CVE-2026-56116Medium· 6.5▾ Sunlitdhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending craf…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash.
dhcpcd >= 10.0.7, < 10.5.0Upgrade past the affected range:
dhcpcd 10.5.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-20193Low· 3.3A flaw was found in the src/list.c of tar 1.33 and earlier
CVE-2025-39890Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_service_ready_ext_event Currently, in ath12k_service_ready_ext_event(), svc_rdy_ext.mac_phy_caps is not freed in the failure ca…
CVE-2022-38178High· 7.5By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak
CVE-2022-38177High· 7.5By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak
CVE-2022-50420Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/hpre - fix resource leak in remove process In hpre_remove(), when the disable operation of qm sriov failed, the following logic should continue to be…
CVE-2022-50418Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: mhi: fix potential memory leak in ath11k_mhi_register() mhi_alloc_controller() allocates a memory space for mhi_ctrl