logo

FreeBSD DHCP Client Flaw Opens Door to Remote Code Execution as Root Privilege

ID: 2d87c03e-b61b-5b9e-a5b6-b74d77b30e03

STIX ID: report--2d87c03e-b61b-5b9e-a5b6-b74d77b30e03

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Ddos

...
...

FreeBSD published an urgent advisory for CVE-2026-42511: a critical RCE in the default IPv4 DHCP client (dhclient) where unescaped double-quotes in the BOOTP file field allow a rogue DHCP server on the same broadcast domain to inject directives that are later executed as root. The flaw carries a CVSS 8.1, affects systems using dhclient, and has been patched across supported branches; mitigations include applying the update and using DHCP snooping on switches to block rogue servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.