CVE Tools

Dhcpcd

23 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Dhcpcd, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

Dhcpcd CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Dhcpcd CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-064
2026-070
2026-080
2026-090

Severity

How the 23 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical313%
  • High835%
  • Medium1148%
  • Low14%

Latest CVEs

The 15 most recently published vulnerabilities affecting Dhcpcd.

  1. CVE-2026-56117dhcpcd Heap Use-After-Free via Control Socket Handling4.7
  2. CVE-2026-56116dhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling6.5
  3. CVE-2026-56114dhcpcd Stack Out-of-Bounds Write in dhcp6_makemessage()5.3
  4. CVE-2026-56113dhcpcd Heap Use-After-Free in dhcp6_deprecateaddrs via DHCPv6 RENEW5.3
  5. CVE-2021-25217A buffer overrun in lease file parsing code can be used to exploit a common vulnerability shared by dhcpd and dhclient7.4
  6. CVE-2019-6470dhcpd: use-after-free error leads crash in IPv6 mode when using mismatched BIND libraries6.5
  7. CVE-2019-11766dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.9.8
  8. CVE-2019-11579dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.5.3
  9. CVE-2019-11578auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks.5.9
  10. CVE-2019-11577dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses.9.8
  11. CVE-2018-5733A malicious client can overflow a reference counter in ISC dhcpd7.5
  12. CVE-2016-1504dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length.7.5
  13. CVE-2016-1503dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attac...9.8
  14. CVE-2012-6698The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted response.7.5
  15. CVE-2012-6700The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response.7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store