{"id":"SUSE-SU-2026:22561-1","summary":"Security update for dhcpcd","details":"This update for dhcpcd fixes the following issue\n\nUpdate to 10.3.2:\n\n- CVE-2025-70102: NULL pointer dereference in `parse_option()` when processing a specially crafted configuration input\n  (bsc#1268761).\n\nChanges for dhcpcd:\n\n * options: Ensure ldop is not NULL dereferenced\n * DHCP: Don't run double EXPIRE hooks on carrier loss\n * DHCP: free the state when dropping on state NONE\n * BSD: don't send uninitialised memory using\n ps_root_indirectioctl\n * Fix fallback_time option\n * IPv4: Ignore DHCP state when building routes\n * route: Routes may not have an interface assinged\n * options: Ensure that an overly long bitflag string does not\n crash\n * options: Don't assume vsio options have an argument\n * common: Cast via uintptr_t rather than unsigned long in UNCONST\n * privsep: Ensure we recv for real after a successful recv\n MSG_PEEK\n * DHCP: Add parentheses to macro definitions\n * ipv6nd: empty IPV6RA_EXPIRE eloop queue when dropping\n * privsep: enforce message boundaries with MSG_EOR on our\n messages\n * Protocols will notify when dhcpcd can exit\n * DHCP: Don't request T1 and T2\n * DHCP: Don't request a lease time\n * DHCP6: Don't exit if using DHCP4 INFORM in non manager mode\n * ND: Route Information Option prefix is optional\n * ipv6: respect slaac hwaddr to really use the hwaddr\n * When stopping all interfaces at exit and releasing,\n remove persistance\n * NetBSD: Delete RTF_CONNECTED route when changing it\n * privsep: Drain the log when the root process is exiting\n * eloop: vastly reworked, kqueue and epoll support on by default\n","modified":"2026-07-15T18:24:11.322616360Z","published":"2026-07-06T20:10:18Z","related":["CVE-2025-70102"],"upstream":["CVE-2025-70102"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622561-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268761"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-70102"}],"affected":[{"package":{"name":"dhcpcd","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/dhcpcd&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.3.2-160000.1.2"}]}],"ecosystem_specific":{"binaries":[{"dhcpcd":"10.3.2-160000.1.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22561-1.json"}},{"package":{"name":"dhcpcd","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/dhcpcd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.3.2-160000.1.2"}]}],"ecosystem_specific":{"binaries":[{"dhcpcd":"10.3.2-160000.1.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22561-1.json"}}],"schema_version":"1.7.5"}