Dhcpcd is a lightweight DHCP client widely embedded across Unix, Linux, and BSD systems, where its narrow product scope belies significant distribution depth in networked infrastructure and embedded devices. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through memory-safety and bounds-checking weakness classes including improper buffer-operation restriction, out-of-bounds reads, and observable discrepancies that reflect the low-level network-parsing demands of a system daemon. Defenders should track this vendor's releases closely given its role in network configuration across many device classes and deployment contexts; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dhcpcd Project over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11577CRITICAL dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses. | Apr 28, 2019 | 9.8 | 61 | NO | NO |
CVE-2016-1503CRITICAL dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which al | Apr 18, 2016 | 9.8 | 33 | NO | NO |
CVE-2019-11766CRITICAL dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature. | May 5, 2019 | 9.8 | 31 | NO | NO |
CVE-2026-56116MEDIUM dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same | Jun 23, 2026 | 6.5 | 30 | NO | NO |
CVE-2026-56114MEDIUM dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-l | Jun 23, 2026 | 6.5 | 30 | NO | NO |
CVE-2026-56113MEDIUM dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafte | Jun 23, 2026 | 6.5 | 29 | NO | NO |
CVE-2026-56117MEDIUM dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged atta | Jun 23, 2026 | 5.5 | 27 | NO | NO |
CVE-2016-1504HIGH dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length. | Feb 7, 2017 | 7.5 | 25 | NO | NO |
CVE-2012-6700HIGH The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response. | Apr 11, 2016 | 7.5 | 24 | NO | NO |
CVE-2012-6699HIGH The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted response. | Apr 11, 2016 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dhcpcd Project.
Media articles that mention a CVE ID that affects a product developed by Dhcpcd Project — matched by CVE ID, not by vendor name.