RHSA-2026:54210MediumCVSS 6.5

Red Hat Security Advisory: dhcpcd security update

Published
August 12, 2026
Last Modified
August 12, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-14258 — dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length IPv6 ND option in Router Advertisement handling

🎯 Affected products14

  • Red Hat Enterprise Linux BaseOS (v. 10)
  • dhcpcd-0:10.0.6-11.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • dhcpcd-0:10.0.6-11.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • dhcpcd-0:10.0.6-11.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • dhcpcd-0:10.0.6-11.el10_2.src as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • dhcpcd-0:10.0.6-11.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • dhcpcd-debuginfo-0:10.0.6-11.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • dhcpcd-debuginfo-0:10.0.6-11.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • dhcpcd-debuginfo-0:10.0.6-11.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • dhcpcd-debuginfo-0:10.0.6-11.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • dhcpcd-debugsource-0:10.0.6-11.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • dhcpcd-debugsource-0:10.0.6-11.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • dhcpcd-debugsource-0:10.0.6-11.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • dhcpcd-debugsource-0:10.0.6-11.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Until an updated package is available, administrators should disable IPv6 Router Advertisement processing on interfaces where it is not required or restrict acceptance of untrusted ICMPv6 Router Advertisements using appropriate network filtering. Systems that rely on IPv6 Stateless Address Autoconfiguration (SLAAC) or Router Advertisement-based network configuration should carefully evaluate the operational impact before applying these mitigations.

🔗 References (4)