{"id":"AZL-90219","summary":"CVE-2026-56116 affecting package dhcpcd for versions less than 10.0.8-2","details":"dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash.","modified":"2026-08-30T05:26:50Z","published":"2026-06-23T17:17:09Z","upstream":["CVE-2026-56116"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56116"}],"affected":[{"package":{"name":"dhcpcd","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/dhcpcd"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.8-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90219.json"}}],"schema_version":"1.9.0"}