CVE Database
/

CVE-2026-42511

Back to search

CVE-2026-42511

Published: Apr 30, 2026

Modified: May 1, 2026

PUBLISHED

Description

The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhclient-script(8), which evaluates it. A rogue DHCP server may be able to execute arbirary code as root on a system running dhclient.

VendorProductVersions

FreeBSD

FreeBSD

affected
15.0-RELEASE - < p7
affected
14.4-RELEASE - < p3
affected
14.3-RELEASE - < p12
affected
13.5-RELEASE - < p13

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now