{"id":"SUSE-SU-2026:23562-1","summary":"Security update for dhcpcd","details":"This update for dhcpcd fixes the following issues:\n\nUpdate to 10.5.0.\n\nSecurity issues fixed:\n\n- CVE-2026-56113: crafted DHCPv6 RENEW reply can lead to a denial of service (bsc#1268980).\n- CVE-2026-56115: crafted DHCPv6 ADVERTISE message can cause a one-byte stack out-of-bounds write (bsc#1268976).\n- CVE-2026-56116: crafted Router Advertisements containing Route Information options with a zero lifetime can lead to a\n  memory leak (bsc#1268974).\n- CVE-2026-56117: crafted privileged command sent over a writable control socket can lead to a heap use-after-free\n  (bsc#1268968).\n\nChanges for dhcpcd:\n\n- 10.5.0:\n  * Add missing SPDX-License tags\n  * Format code with clang-format v19\n  * privsep: Change IPC to use SOCK_STREAM\n  * BPF: Split OS specific code out into own files and add libpcap\n    support\n  * hooks: Escape interface names and use printf\n  * Delete DHCPv6 IA FD from the loop before closing it\n  * eloop: Use kqueue or epoll to wait for a fd to become ready\n  * Darwin: Add initial support for macOS\n  * Import latest pidfile from NetBSD\n  * BPF: Improve headers\n  * compat: Add support for getprogname(3)\n  * route: Rework rt structure so sockaddrs are pointers\n  * dhcp-common: Escape ifname for lease file\n  * privsep: smaller buffer size without INET6\n  * script: add ifxname as the escaped string\n  * time.h always pulls in struct timespec\n  * route: Use HAVE_RT_MISSFILTER rather than a generic BSD define\n  * privsep: Test defines for all ioctls\n  * if: if_init inits the interface from the kernel\n  * privsep: Add ps_root_gethostname\n  * DHCP: Don't really expire the lease when testing\n  * DHCP: Don't add a trailing : on vendor if no machine arch\n  * privsep: guard setproctitle and only use compat on linux\n  * options: Remove some const to fix compile warnings\n  * privsep: Don't open PF_INET socket for each ioctl\n  * sun: Enable building for privsep\n  * script: Use correct buffer length variable\n  * privsep: Remove PS_BUFLEN\n  * privsep: Simplify readerror\n  * timezone: disallow directory traversal\n  * privsep: ps_root_readfile should return the real file size\n  * linux: Ensure NLA data boundaries are valid\n  * options: Fix userclass boundary\n  * ND6: fix OOB reject mask for an undefined option.\n  * DHCP6: Ensure IA_PD Prefix Lenth is valid\n  * ND: Enforce require and reject policy\n  * ARP: check we have enough to read the frame header\n  * hooks: Quote assignment of compat vars correctly\n  * udev: Ensure we have a subsystem, action and ifname\n  * Fix CI build\n  * DHCP: Santize messages from servers for output\n  * ARP: Iterate over states safely as the cb could remove ours\n  * privsep: Check data is terminated when a string\n  * auth: clear keys with memset_explicit\n  * auth: Ensure remaining dlen matches hash digest length\n  * hooks: don't read past truncated ip6 address starting fe\n  * ipv6: Only regen temp addrs with sufficent pltime\n  * eloop: Improve timespecdiff\n  * eloop: Fix compile warning where UTIME_MAX is a calculation\n  * vsio: Allow zero length options\n  * DHCP6: Fix configuring the suffix to delegated prefixes\n  * IPv6: Fix numerous issues extending temporary address times\n  * capsicum: Avoid some overflow issues in privsep sysctl\n  * script: Fix buffer over and under flows in script_buftoenv\n  * IPv4: uset old_ia when adding an address causes early removal\n  * dhcp: add configurable backoff parameters for DHCPv4\n  * options: Introdce policy groups\n  * Build all the targets on macos\n  * control: remove unprivileged socket\n  * DHCP: deconfigure even when state is NULL or NONE\n","modified":"2026-09-29T18:23:08.595740953Z","published":"2026-08-30T14:33:20Z","related":["CVE-2026-56113","CVE-2026-56115","CVE-2026-56116","CVE-2026-56117"],"upstream":["CVE-2026-56113","CVE-2026-56115","CVE-2026-56116","CVE-2026-56117"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623562-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268968"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268974"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268976"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268980"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56113"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56115"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56116"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56117"}],"affected":[{"package":{"name":"dhcpcd","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/dhcpcd&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.5.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"dhcpcd":"10.5.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23562-1.json"}},{"package":{"name":"dhcpcd","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/dhcpcd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.5.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"dhcpcd":"10.5.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23562-1.json"}}],"schema_version":"1.9.0"}