{"id":"CVE-2026-48715","summary":"radvdump's Route Information Option Parser has a Stack Buffer Overflow","details":"radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, `print_ff()` copies up to 2032 bytes from attacker-controlled packet data into a 16-byte `struct in6_addr` on the stack, overflowing by up to 2016 bytes. Note that the main `radvd` daemon is not affected by the vulnerability. Version 2.21 patches the issue.","aliases":["GHSA-52px-gh9p-m379"],"modified":"2026-08-12T16:09:41.652413Z","published":"2026-06-19T19:18:23.721Z","related":["SUSE-SU-2026:22836-1","SUSE-SU-2026:3055-1","openSUSE-SU-2026:11161-1","openSUSE-SU-2026:21400-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48715.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48715.json"},{"type":"ADVISORY","url":"https://github.com/radvd-project/radvd/security/advisories/GHSA-52px-gh9p-m379"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48715"},{"type":"FIX","url":"https://github.com/radvd-project/radvd/commit/068bde13e3fd6a5fcdb6859e6a2acd293a325dc5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/radvd-project/radvd","events":[{"introduced":"0"},{"fixed":"a8500f4035b52028c90b0a938dfe8cd65e38fb50"},{"fixed":"068bde13e3fd6a5fcdb6859e6a2acd293a325dc5"}],"database_specific":{"cpe":"cpe:2.3:a:radvd.litech:radvd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.21"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.20","v2.20_rc1","v2.19","v2.18","v2.18-rc1","v2.17","v2.17-rc1","v2.16","v2.16-rc1","v2.15","v2.14","v2.13","v2.12","v2.11","v2.10","v2.9","v2.8","v2.7","v2.6","v2.5","v2.4","v2.3","v2.2","v2.1","v2.0","v2.0-rc5","v2.0-rc4","v2.0-rc3","v2.0-rc2","v2.0-rc1","v1.11","v1.10.0","v1.10.0-rc2","v1.10.0-rc1","v1.9.9","v1.9.8","v1.9.7","v1.9.6","v1.9.5","v1.9.4","v1.9.3","v1.9.2","v1.9.1","v1.9","v1.8.5","v1.8.4","v1.8.3","v1.8.2","v1.8","v1.6","v1.4","v1.3","v1.2","v1.1","v1.0","v1.0.rc2","v1.0.rc1","v0.9.1","v0.9","v0.8","v0.7.3","v0.7.2","v0.7.1","v0.7.0","v0.6.2","v0.6.1","v0.5.0","v0.4.2","v0.4.1"],"database_specific":{"vanir_signatures_modified":"2026-08-12T16:09:41Z","vanir_signatures":[{"digest":{"function_hash":"273387529576921906176241256072357170167","length":11282},"id":"CVE-2026-48715-60557fbf","signature_type":"Function","signature_version":"v1","source":"https://github.com/radvd-project/radvd/commit/068bde13e3fd6a5fcdb6859e6a2acd293a325dc5","target":{"function":"print_ff","file":"radvdump.c"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/radvd-project/radvd/commit/068bde13e3fd6a5fcdb6859e6a2acd293a325dc5","target":{"file":"radvdump.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["204279637341286730851612682148984822788","179228105070379554619936245679117927336","266460830546425982891231426771265971588","266196632030535226975638533241326312563","42604694817498147073949191103889022809","155488865718896652442396632792043226601","335863365713435615548481820956526947416","123871383680000808334089844424418784924","138414748987559162549979050306289768485","287985769062327729196173803977772226599","150524644079361186782325576170330916157","221922380575791313496121061776331904452","121445756852919718756808899675642697432","196168023809331950079188695490454990966","47130731555757710359022290636823069299","303910976721461265294194620883505161847","169891294782602114272526727658638384131","101397099393048821897516076365436009747","94087830382373932447627154932299948819","312371420201315596582457775651910618700","81919229339467377411242779454244745290","126979662973697159785902789589807066732","266345590982183066545752615823478073425","160754641852520491817772196938546490688","148566626658691806959583014175974413333","63762453603185769069011005911648177687","136177738365157226979445642117805475831","52415690380542474451512788658503216655","190024475839325636452660426879348259311","57795909545260118408593846075896338768","68780807019557804359794733330979711445","159410636230311241871833063080252930447","166348222396367000088335206702835809283","313983919933746190833998805022708497953","62329984683957258888151371376005753756","53014346261845100464265386499601943013","28839620575596498763611469276192216532","282771370230380497620412181800093113351","123278308145224393748686168193802669580","234540347887386614400031364337355191397","60206872650641779487196680180461543424","217545908894727785962214358947209865592","246367099935830126123733174232022327611","137977868032711989711879668434088958508","198900346863287461532295326454693982304"]},"id":"CVE-2026-48715-d8da5127"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/radvd-project/radvd/commit/068bde13e3fd6a5fcdb6859e6a2acd293a325dc5","target":{"file":"radvdump.c","function":"main"},"deprecated":false,"digest":{"length":2047,"function_hash":"219484983673530557685427238350200582186"},"id":"CVE-2026-48715-e6b5471e"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48715.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}