logo

FreeBSD DHCP Client Flaw Allows Remote Code Execution as Root

ID: affa3eeb-9cbd-5fcb-b979-3c596ceb510f

STIX ID: report--affa3eeb-9cbd-5fcb-b979-3c596ceb510f

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-04

Date Updated: 2026-05-08

Author: AnuPriya

...
...

FreeBSD released a critical advisory for CVE-2026-42511: a flaw in the default IPv4 DHCP client (dhclient) that permits attackers on the same broadcast domain running a rogue DHCP server to inject malicious configuration (via unescaped embedded quotes) into DHCP lease files, which are later executed with root privileges when reprocessed; all supported FreeBSD branches are affected, patches are available and administrators are urged to update immediately and consider DHCP snooping as a network-level mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.