RHSA-2026:54210MediumCVSS 6.5
Red Hat Security Advisory: dhcpcd security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-14258 — dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length IPv6 ND option in Router Advertisement handling
🎯 Affected products14
- Red Hat Enterprise Linux BaseOS (v. 10)
- dhcpcd-0:10.0.6-11.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- dhcpcd-0:10.0.6-11.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- dhcpcd-0:10.0.6-11.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- dhcpcd-0:10.0.6-11.el10_2.src as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- dhcpcd-0:10.0.6-11.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- dhcpcd-debuginfo-0:10.0.6-11.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- dhcpcd-debuginfo-0:10.0.6-11.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- dhcpcd-debuginfo-0:10.0.6-11.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- dhcpcd-debuginfo-0:10.0.6-11.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- dhcpcd-debugsource-0:10.0.6-11.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- dhcpcd-debugsource-0:10.0.6-11.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- dhcpcd-debugsource-0:10.0.6-11.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- dhcpcd-debugsource-0:10.0.6-11.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Until an updated package is available, administrators should disable IPv6 Router Advertisement processing on interfaces where it is not required or restrict acceptance of untrusted ICMPv6 Router Advertisements using appropriate network filtering. Systems that rely on IPv6 Stateless Address Autoconfiguration (SLAAC) or Router Advertisement-based network configuration should carefully evaluate the operational impact before applying these mitigations.