CVE-2026-42511CWE-149

Remote code execution via malicious DHCP options

High · published April 30, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
36.0
In the wild
Unconfirmed
What it is

The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhclient-script(8), which evaluates it.

A rogue DHCP server may be able to execute arbirary code as root on a system running dhclient.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00431 · 36.0th percentile
Weakness
CWE-149 · Improper Neutralization of Quoting Syntax
Published
2026-04-30T06:56Z
EPSS history
Timeline
  • 30 APR 06:56Z
    Remote code execution via malicious DHCP options
    cvelistv5