FreeBSD DHCP Client Flaw Allows Remote Code Execution as Root
ID: affa3eeb-9cbd-5fcb-b979-3c596ceb510f
STIX ID: report--affa3eeb-9cbd-5fcb-b979-3c596ceb510f
Feed Name: Cyber Press
FreeBSD released a critical advisory for CVE-2026-42511: a flaw in the default IPv4 DHCP client (dhclient) that permits attackers on the same broadcast domain running a rogue DHCP server to inject malicious configuration (via unescaped embedded quotes) into DHCP lease files, which are later executed with root privileges when reprocessed; all supported FreeBSD branches are affected, patches are available and administrators are urged to update immediately and consider DHCP snooping as a network-level mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
