CVE-2026-42511
Published: Apr 30, 2026
Modified: May 1, 2026
Description
The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhclient-script(8), which evaluates it. A rogue DHCP server may be able to execute arbirary code as root on a system running dhclient.
| Vendor | Product | Versions |
|---|---|---|
FreeBSD | FreeBSD | affected 15.0-RELEASE - < p7affected 14.4-RELEASE - < p3affected 14.3-RELEASE - < p12affected 13.5-RELEASE - < p13 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now