Vulnerability Description
The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhclient-script(8), which evaluates it. A rogue DHCP server may be able to execute arbirary code as root on a system running dhclient.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 13.5 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-42511?
CVE-2026-42511 is a vulnerability with a CVSS score of 8.1 (HIGH). The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by d...
How severe is CVE-2026-42511?
CVE-2026-42511 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-42511?
Check the references section above for vendor advisories and patch information. Affected products include: Freebsd Freebsd.