dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash.
1:10.0.2-3ubuntu31:10.0.5-11:10.0.5-21:10.0.5-31:10.0.5-41:10.0.5-51:10.0.6-11:10.0.6-1ubuntu11:10.0.6-1ubuntu21:10.0.6-1ubuntu3+2 more1:10.1.0-101:10.1.0-111:10.1.0-121:10.1.0-81:10.2.4-31:10.2.4-41:10.2.4-41:10.3.0-21:10.3.0-31:10.3.0-7Exploitability
AV:AAC:LAT:NPR:NUI:NVulnerable System
VC:NVI:NVA:HSubsequent System
SC:NSI:NSA:NCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N