{"id":"openSUSE-SU-2026:21669-1","summary":"Security update for wicked","details":"This update for wicked fixes the following issues:\n\nChanges in wicked:\n\n- Fix two OOB reads in ni_capture_inspect_udp_header and improve:\n  - Reject packets with ip_len \u003c ihl to avoid a size_t underflow of the\n    UDP length, which the checksum truncates to uint16_t (bsc#1274627,\n    CVE-2026-71401).\n  - Set payload_len to the remaining payload, not ip_len, which over-read\n    the DHCP option walker by ihl + 8 bytes past the buffer (bsc#1274627,\n    CVE-2026-71402).\n  - Avoid checksumming packets that fail the length/protocol checks and\n    tidy up the debug messages (bsc#1274627).\n  - Fix underflow check in ni_dhcp4_option_next to handle option code\n    and length separately as the END and PAD options don't have length\n    (bsc#1274627).\n\n  Thanks to Daniel Birtwhistle for discovering and reporting the issues.\n","modified":"2026-08-28T18:23:33.279592107Z","published":"2026-08-27T16:26:05Z","related":["CVE-2026-71401","CVE-2026-71402"],"upstream":["CVE-2026-71401","CVE-2026-71402"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274627"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-71401"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-71402"}],"affected":[{"package":{"name":"wicked","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/wicked&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.80-bp160.2.1"}]}],"ecosystem_specific":{"binaries":[{"wicked-nbft":"0.6.80-bp160.2.1","wicked-service":"0.6.80-bp160.2.1","wicked":"0.6.80-bp160.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21669-1.json"}}],"schema_version":"1.9.0"}