{"id":"CVE-2026-71401","summary":"wicked: integer underflow of the UDP length in ni_capture_inspect_udp_header() leads to an out-of-bounds read","details":"An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c does not verify that the IP total length field (ip_len) is at least as large as the IP header length (ihl) before subtracting the header length. An unauthenticated attacker on the same network can thereby trigger an out-of-bounds read past the receive buffer in the wicked DHCPv4 client (wickedd-dhcp4), which can crash the daemon depending on the process memory layout. No information disclosure has been demonstrated. This issue affects wicked up to and including version 0.6.80.","modified":"2026-09-04T18:26:39.978449370Z","published":"2026-08-27T15:01:27.342Z","related":["SUSE-SU-2026:3837-1","SUSE-SU-2026:3839-1","SUSE-SU-2026:3840-1","SUSE-SU-2026:3841-1","SUSE-SU-2026:3842-1","openSUSE-SU-2026:11636-1","openSUSE-SU-2026:21669-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71401.json","cna_assigner":"suse","cwe_ids":["CWE-191"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71401.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71401"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1274627"},{"type":"FIX","url":"https://github.com/openSUSE/wicked/pull/1079"},{"type":"PACKAGE","url":"https://github.com/openSUSE/wicked"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opensuse/wicked","events":[{"introduced":"0"},{"last_affected":"d6b6f7d298363f8c7ba56bd3e99a2980d5e294cf"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.6.80"}],"source":"AFFECTED_FIELD"}}],"versions":["version-0.6.80","version-0.6.78","version-0.6.77","version-0.6.76","version-0.6.75","version-0.6.73","version-0.6.74","version-0.6.72","version-0.6.70","version-0.6.71","version-0.6.69","version-0.6.68","version-0.6.67","version-0.6.64","version-0.6.60","version-0.6.66","version-0.6.65","version-0.6.62","version-0.6.61","version-0.6.57","version-0.6.56","version-0.6.55","version-0.6.54","version-0.6.52","version-0.6.53","version-0.6.51","version-0.6.50","version-0.6.49","version-0.6.48","version-0.6.31","version-0.6.47","version-0.6.46","version-0.6.45","version-0.6.44","version-0.6.43","version-0.6.42","version-0.6.40","version-0.6.41","version-0.6.39","version-0.6.38","version-0.6.37","version-0.6.36","version-0.6.35","version-0.6.34","version-0.6.33","version-0.6.32","version-0.6.30","version-0.6.29","version-0.6.28","version-0.6.27","version-0.6.26","version-0.6.25","version-0.6.24","version-0.6.23","version-0.6.22","version-0.6.21","version-0.6.20","version-0.6.19","version-0.6.18","version-0.6.17","version-0.6.16","version-0.6.15","version-0.6.14","version-0.6.13","version-0.6.12","version-0.6.11","version-0.6.10","version-0.6.9","version-0.6.8","version-0.6.7","version-0.6.6","version-0.6.5","version-0.6.4","version-0.6.3","version-0.6.2","version-0.6.1","version-0.6.0","version-0.5.38","version-0.5.37","version-0.5.36","version-0.5.35","version-0.5.34","version-0.5.33","version-0.5.32","version-0.5.31","version-0.5.30","version-0.5.29","version-0.5.28","version-0.5.27","version-0.5.26","version-0.5.25","version-0.5.24","version-0.5.23","version-0.5.22","version-0.5.21","version-0.5.20","version-0.5.19","version-0.5.18","version-0.5.17","version-0.5.16","version-0.5.15","version-0.5.14","version-0.5.13","version-0.5.12","version-0.5.11","version-0.5.10","version-0.5.9","version-0.5.8","version-0.5.7","factory-rq-221054","version-0.5.6","factory-rq-214794","version-0.5.5","factory-rq-214306","factory-rq-213496","version-0.5.4","factory-2014010901","version-0.5.3","factory-2013120601","version-0.5.2","factory-2013100201","version-0.5.1","factory-2013092701","factory-2013091802","factory-2013091801","factory-2013091601"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-71401.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}