Skip to content
Red HatCVE-2026-14258

Red Hat dhcpcd: resource exhaustion

Medium6.5CVE-2026-14258 · Published Jul 1, 2026 · updated Aug 12, 2026

A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Advertisement containing a zero-length Neighbor Discovery option can bypass validation during packet storage and later be reparsed without adequate validation, causing the parser to enter a non-advancing loop. Successful exploitation may result in excessive CPU consumption, leading to a denial of service.

Red Hat advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Satellite 6: improper access control
Medium6.5Jul 1
Red Hat Satellite 6: information disclosure
Medium4.3Jul 1
Red Hat Satellite 6: information disclosure
Medium6.5Jul 1
Red Hat Enterprise Linux: null pointer dereference
Medium6.5Jul 1
Red Hat Enterprise Linux: resource exhaustion
Medium5.5Jul 1
Red Hat Feast Feature Server: denial of service
Critical9.1Jul 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.