Heap-based buffer overflow in FreeBSD - CVE-2026-42512
Published: April 30, 2026
FreeBSD
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in dhclient when processing a crafted DHCP offer while building environment entries for dhclient-script. A remote attacker can send a specially crafted DHCP packet to execute arbitrary code or cause a denial of service.
Exploitation requires the attacker to be on the same broadcast domain and able to respond to DHCP requests.