Skip to content
openSUSE Wicked Important Indirect Shell Command Injection Fix 2026-3840

openSUSE Wicked Important Indirect Shell Command Injection Fix 2026-3840

Linuxsecurity LinuxSecurity Advisories August 28, 2026

Find practical guidance for preventing, investigating, and responding to Linux security problems. Find practical guidance for preventing, investigating, and responding to Linux security problems. _ Review Linux Privileges ×

This update for wicked fixes the following issues:

Update to version 0.6.79.

* CVE-2026-44932: indirect remote shell command injection due to insufficient

sanitization of DHCP options written to `/run/wicked/leaseinfo.*` files

* CVE-2026-71401: out-of-bounds read due to IP length underflow in checksum

handling of DHCPv4 capture parsing (bsc#1274627).

* CVE-2026-71402: out-of-bounds read due to DHCP option reader being extended

beyond provided allocation in DHCPv4 capture parsing (bsc#1274627).

* Fix to escape single-quotes in leaseinfo dump output used by the `wicked

test dhcp4` and `wicked test dhcp6` and written to the

`/run/wicked/leaseinfo.*` files, e.g. to pass them to `netconfig`.

* Fix `posix-tz-dbname` and `tz-string` option processing checks to permit

only valid characters according to RFC4833.

* Discard string values containing single-quotes in other options.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3840=1

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3840=1

zypper in -t patch SUSE-2026-3840=1

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)

* wicked-nbft-0.6.79-150600.11.20.1

* wicked-debuginfo-0.6.79-150600.11.20.1

* wicked-debugsource-0.6.79-150600.11.20.1

* wicked-0.6.79-150600.11.20.1

* wicked-service-0.6.79-150600.11.20.1

* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)

* wicked-nbft-0.6.79-150600.11.20.1

* wicked-debuginfo-0.6.79-150600.11.20.1

* wicked-service-0.6.79-150600.11.20.1

* wicked-0.6.79-150600.11.20.1

* wicked-debugsource-0.6.79-150600.11.20.1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)

* wicked-nbft-0.6.79-150600.11.20.1

* wicked-debuginfo-0.6.79-150600.11.20.1

* wicked-service-0.6.79-150600.11.20.1

* wicked-0.6.79-150600.11.20.1

* wicked-debugsource-0.6.79-150600.11.20.1

*

*

*

*

*

*

Get the latest Linux and open source security news straight to your inbox.