Vulnerability Description
dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged attackers to trigger memory corruption when privilege separation is disabled. Attackers can connect to the control socket and send a privileged command such as -x, causing control_recvdata() to free the client object while the same READ+HANGUP event subsequently reaches control_hangup() with the stale pointer, resulting in a use-after-free condition exploitable in deployments using --disable-privsep or where privsep initialization has failed with the control socket operating in mode 0666.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dhcpcd Project | Dhcpcd | <= 10.3.2 |
Related Weaknesses (CWE)
References
- https://github.com/NetworkConfiguration/dhcpcd/commit/78ea09ed1633a583dbcde6e7baPatch
- https://www.vulncheck.com/advisories/dhcpcd-heap-use-after-free-via-control-sockThird Party Advisory
FAQ
What is CVE-2026-56117?
CVE-2026-56117 is a vulnerability with a CVSS score of 4.7 (MEDIUM). dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged attackers to trigger mem...
How severe is CVE-2026-56117?
CVE-2026-56117 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56117?
Check the references section above for vendor advisories and patch information. Affected products include: Dhcpcd Project Dhcpcd.