{"id":"GO-2026-6237","summary":"Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp","details":"In github.com/insomniacslk/dhcp/dhcpv4/nclient4, BroadcastRawUDPConn.ReadFrom does not validate that the IPv4 payload length is sufficient to hold a UDP header before calculating the DHCP payload length. A frame with an IPv4 total-length field specifying fewer than eight payload bytes results in a negative DHCP length, causing a panic in buf.Consume due to a negative slice bound.","modified":"2026-08-19T15:41:56.905027993Z","published":"2026-08-18T16:38:10Z","related":["CGA-vf2p-ppx4-2xq7"],"database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-6237","review_status":"REVIEWED"},"references":[{"type":"FIX","url":"https://github.com/insomniacslk/dhcp/commit/c76316d4aa825673b208730779843d0711021e81"}],"affected":[{"package":{"name":"github.com/insomniacslk/dhcp","ecosystem":"Go","purl":"pkg:golang/github.com/insomniacslk/dhcp"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20260719225207-c76316d4aa82"}]}],"ecosystem_specific":{"imports":[{"symbols":["BroadcastRawUDPConn.ReadFrom"],"path":"github.com/insomniacslk/dhcp/dhcpv4/nclient4"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6237.json"}}],"schema_version":"1.9.0"}