openSUSE-SU-2026:21669-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21669-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21669-1
Upstream
CVE (2)
Related
Published
2026-08-27T16:26:05Z
Modified
2026-08-28T18:23:33Z
Summary
Security update for wicked
Details

This update for wicked fixes the following issues:

Changes in wicked:

  • Fix two OOB reads in ni_capture_inspect_udp_header and improve:

    • Reject packets with ip_len < ihl to avoid a size_t underflow of the UDP length, which the checksum truncates to uint16_t (bsc#1274627, CVE-2026-71401).
    • Set payload_len to the remaining payload, not ip_len, which over-read the DHCP option walker by ihl + 8 bytes past the buffer (bsc#1274627, CVE-2026-71402).
    • Avoid checksumming packets that fail the length/protocol checks and tidy up the debug messages (bsc#1274627).
    • Fix underflow check in ni_dhcp4_option_next to handle option code and length separately as the END and PAD options don't have length (bsc#1274627).

    Thanks to Daniel Birtwhistle for discovering and reporting the issues.

References

Affected packages

openSUSE:Leap 16.0 / wicked

Package

Name
wicked
Purl
pkg:rpm/opensuse/wicked&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.6.80-bp160.2.1

Ecosystem specific

{
    "binaries":  [
        {
            "wicked":  "0.6.80-bp160.2.1",
            "wicked-nbft":  "0.6.80-bp160.2.1",
            "wicked-service":  "0.6.80-bp160.2.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21669-1.json"