{"id":"CVE-2019-11766","details":"dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.","modified":"2026-08-27T08:14:23.012659Z","published":"2019-05-05T06:29:00.223Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"},{"introduced":"9.0"},{"last_affected":"9.0"},{"introduced":"10.0"},{"last_affected":"10.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"}]},"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/108172"},{"type":"FIX","url":"https://bugs.debian.org/928440"},{"type":"FIX","url":"https://roy.marples.name/archives/dhcpcd-discuss/0002428.html"},{"type":"FIX","url":"https://roy.marples.name/cgit/dhcpcd.git/commit/?h=dhcpcd-7&id=896ef4a54b0578985e5e1360b141593f1d62837b"},{"type":"FIX","url":"https://roy.marples.name/cgit/dhcpcd.git/commit/?h=dhcpcd-7&id=c1ebeaafeb324bac997984abdcee2d4e8b61a8a8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/NetworkConfiguration/dhcpcd","events":[{"introduced":"0"},{"fixed":"32ecbd429a7b3911b6763cb4e4b06b0b40f84270"},{"introduced":"dbbb02133ce761dafb42daef0b2eb6eaf8bf403d"},{"fixed":"d30538898e39cc9a49ced4e67e91013d1d84a2c2"}],"database_specific":{"cpe":"cpe:2.3:a:dhcpcd_project:dhcpcd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"6.11.7"},{"introduced":"7.0.0"},{"fixed":"7.2.2"}],"source":"CPE_RANGE"}}],"versions":["v7.2.1","v6.11.6","v7.2.0","v7.1.1","v7.1.0","v7.0.8","v7.0.7","v7.0.6","v7.0.5b","v7.0.5a","v7.0.5","v7.0.4","v7.0.3","v7.0.2","v7.0.1","v7.0.0","v6.11.5","v6.11.4","v6.11.3","v6.11.2","v6.11.1","v6.11.0","v6.10.3","v6.10.2","v6.10.1","v6.10.0","v6.9.4","v6.9.3","v6.9.2","v6.9.1","v6.9.0","v6.8.2","v6.8.1","v6.8.0","v6.7.1","v6.7.0","v6.6.7","v6.6.6","v6.6.5","v6.6.4","v6.6.3","v6.6.2","v6.6.1","v6.6.0","v6.5.1","v6.5.0","v6.4.7","v6.4.6","v6.4.5","v6.4.4","v6.4.3","v6.4.2","v6.4.1","v6.4.0","v6.3.2","v6.3.1","v6.3.0","v6.2.1","v6.2.0","v5.5.6","v6.1.0","v6.0.5","v6.0.4","v6.0.3","v6.0.2","v6.0.1","v6.0.0","v5.99.7","v5.99.6","v5.99.3","v5.6.2","v5.6.1","v5.6.0","v5.5.5","v5.5.4","v5.5.3","v5.5.2","v5.5.1","v5.5.0","v5.2.12","v5.2.11","v5.2.10","v5.2.9","v5.2.7","v5.2.6","v5.2.4","v5.2.3","v5.2.2","v5.2.1","v5.2.0","v5.1.5","v5.1.4","v5.1.3","v5.1.2","v5.1.1","v5.1.0","v5.0.6","v5.0.5","v5.0.4","v5.0.3","v5.0.2","v5.0.1","v3.2.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11766.json","vanir_signatures_modified":"2026-08-27T08:14:23Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/NetworkConfiguration/dhcpcd/commit/d30538898e39cc9a49ced4e67e91013d1d84a2c2","target":{"file":"src/dhcp6.c","function":"dhcp6_findpd"},"deprecated":false,"digest":{"function_hash":"129949654370244262757538485416123606766","length":3042},"id":"CVE-2019-11766-e16b9d3d","signature_type":"Function"},{"source":"https://github.com/NetworkConfiguration/dhcpcd/commit/d30538898e39cc9a49ced4e67e91013d1d84a2c2","target":{"file":"src/dhcp6.c"},"deprecated":false,"digest":{"line_hashes":["128791362724316076833846390335608624616","276512548865701510008981561576257645523","164597777333323718200872289213334073819","37736796150810945481206810595216785099","43626031906383246725332989478497325814","12939491439161782283134484832739147034","56198155499831416563622155107367737444","278973541740820641167815533192217982337","231857893143996889906446267693147760429"],"threshold":0.9},"id":"CVE-2019-11766-e35b638e","signature_type":"Line","signature_version":"v1"}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/networkconfiguration/dhcpcd","events":[{"introduced":"0"},{"fixed":"32ecbd429a7b3911b6763cb4e4b06b0b40f84270"},{"introduced":"dbbb02133ce761dafb42daef0b2eb6eaf8bf403d"},{"fixed":"d30538898e39cc9a49ced4e67e91013d1d84a2c2"}],"database_specific":{"cpe":"cpe:2.3:a:dhcpcd_project:dhcpcd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"6.11.7"},{"introduced":"7.0.0"},{"fixed":"7.2.2"}],"source":"CPE_RANGE"}}],"versions":["v7.2.1","v6.11.6","v7.2.0","v7.1.1","v7.1.0","v7.0.8","v7.0.7","v7.0.6","v7.0.5b","v7.0.5a","v7.0.5","v7.0.4","v7.0.3","v7.0.2","v7.0.1","v7.0.0","v6.11.5","v6.11.4","v6.11.3","v6.11.2","v6.11.1","v6.11.0","v6.10.3","v6.10.2","v6.10.1","v6.10.0","v6.9.4","v6.9.3","v6.9.2","v6.9.1","v6.9.0","v6.8.2","v6.8.1","v6.8.0","v6.7.1","v6.7.0","v6.6.7","v6.6.6","v6.6.5","v6.6.4","v6.6.3","v6.6.2","v6.6.1","v6.6.0","v6.5.1","v6.5.0","v6.4.7","v6.4.6","v6.4.5","v6.4.4","v6.4.3","v6.4.2","v6.4.1","v6.4.0","v6.3.2","v6.3.1","v6.3.0","v6.2.1","v6.2.0","v5.5.6","v6.1.0","v6.0.5","v6.0.4","v6.0.3","v6.0.2","v6.0.1","v6.0.0","v5.99.7","v5.99.6","v5.99.3","v5.6.2","v5.6.1","v5.6.0","v5.5.5","v5.5.4","v5.5.3","v5.5.2","v5.5.1","v5.5.0","v5.2.12","v5.2.11","v5.2.10","v5.2.9","v5.2.7","v5.2.6","v5.2.4","v5.2.3","v5.2.2","v5.2.1","v5.2.0","v5.1.5","v5.1.4","v5.1.3","v5.1.2","v5.1.1","v5.1.0","v5.0.6","v5.0.5","v5.0.4","v5.0.3","v5.0.2","v5.0.1","v3.2.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11766.json","vanir_signatures_modified":"2026-08-27T08:14:23Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["128791362724316076833846390335608624616","276512548865701510008981561576257645523","164597777333323718200872289213334073819","37736796150810945481206810595216785099","43626031906383246725332989478497325814","12939491439161782283134484832739147034","56198155499831416563622155107367737444","278973541740820641167815533192217982337","231857893143996889906446267693147760429"],"threshold":0.9},"id":"CVE-2019-11766-03ad4df6","signature_type":"Line","signature_version":"v1","source":"https://github.com/networkconfiguration/dhcpcd/commit/d30538898e39cc9a49ced4e67e91013d1d84a2c2","target":{"file":"src/dhcp6.c"}},{"deprecated":false,"digest":{"function_hash":"129949654370244262757538485416123606766","length":3042},"id":"CVE-2019-11766-0a25a507","signature_type":"Function","signature_version":"v1","source":"https://github.com/networkconfiguration/dhcpcd/commit/d30538898e39cc9a49ced4e67e91013d1d84a2c2","target":{"file":"src/dhcp6.c","function":"dhcp6_findpd"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}