Skip to content
SUSE Wicked Important Indirect Remote Shell Injection Vuln 2026-3840

SUSE Wicked Important Indirect Remote Shell Injection Vuln 2026-3840

Linuxsecurity LinuxSecurity Advisories August 28, 2026

Find practical guidance for preventing, investigating, and responding to Linux security problems. Find practical guidance for preventing, investigating, and responding to Linux security problems. _ Review Linux Privileges ×

## This update for wicked fixes the following issues: Update to version 0.6.79. * CVE-2026-44932: indirect remote shell command injection due to insufficient sanitization of DHCP options written to `/run/wicked/leaseinfo.*` files (bsc#1265221). * CVE-2026-71401: out-of-bounds read due to IP length underflow in checksum handling of DHCPv4 capture parsing (bsc#1274627). * CVE-2026-71402: out-of-bounds read due to DHCP option reader being extended beyond provided allocation in DHCPv4 capture parsing (bsc#1274627). Changes for wicked: * Version 0.6.79: * Fix to escape single-quotes in leaseinfo dump output used by the `wicked test dhcp4` and `wicked test dhcp6` and written to the `/run/wicked/leaseinfo.*` files, e.g. to pass them to `netconfig`.

## This update for wicked fixes the following issues: Update to version 0.6.79. * CVE-2026-44932: indirect remote shell command injection due to insufficient sanitization of DHCP options written to `/run/wicked/leaseinfo.*` files (bsc#1265221). * CVE-2026-71401: out-of-bounds read due to IP length underflow in checksum handling of DHCPv4 capture parsing (bsc#1274627). * CVE-2026-71402: out-of-bounds read due to DHCP option reader being extended beyond provided allocation in DHCPv4 capture parsing (bsc#1274627). Changes for wicked: * Version 0.6.79: * Fix to escape single-quotes in leaseinfo dump output used by the `wicked test dhcp4` and `wicked test dhcp6` and written to the `/run/wicked/leaseinfo.*` files, e.g. to pass them to `netconfig`.

* CVE-2026-44932 ( SUSE ): 5.8

CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H

* CVE-2026-44932 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2026-44932 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2026-71401 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-71401 ( NVD ): 5.3

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2026-71402 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

* CVE-2026-71402 ( NVD ): 5.3

Announcement ID: SUSE-SU-2026:3840-1 Release Date: 2026-08-27T12:21:23Z Rating: important

Get the latest Linux and open source security news straight to your inbox.