Critical Vulnerabilities in openSUSE Wicked DHCP Components

Critical Vulnerabilities in openSUSE Wicked DHCP Components

First seen 28 Aug 2026, 03:54 UTC Linuxsecurity 72.0

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities affecting the openSUSE Wicked DHCP components were disclosed, including CVE-2026-71401 and CVE-2026-71402, both published on 2026-08-27. These vulnerabilities involve out-of-bounds reads that could potentially lead to information disclosure. Additionally, CVE-2026-44932, published on 2026-06-16, allows for indirect remote shell command injection due to insufficient sanitization of DHCP options. Affected systems include various versions of SUSE Linux Enterprise and openSUSE Leap. Administrators are advised to apply the patches immediately using the recommended installation methods. The vulnerabilities were confirmed by the vendor and are critical in nature, affecting a wide range of deployments. The current status is that patches are available, and users are urged to update their systems promptly.

Key Points: • Three critical CVEs affect openSUSE Wicked components. • CVE-2026-71401 and CVE-2026-71402 involve out-of-bounds reads. • CVE-2026-44932 allows indirect remote shell command injection.

Timeline

2026-06-16
CVE-2026-44932 published
Indirect remote shell command injection vulnerability discovered in Wicked DHCP options.
Linuxsecurity
2026-08-27
CVE-2026-71401 published
Out-of-bounds read vulnerability due to IP length underflow in DHCPv4 parsing confirmed.
Linuxsecurity
2026-08-27
CVE-2026-71402 published
Out-of-bounds read vulnerability in DHCP option reader confirmed.
Linuxsecurity
2026-08-28
Patches released for vulnerabilities
SUSE released patches for the identified vulnerabilities in Wicked components, urging users to update.
Linuxsecurity