- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Martin-Éric Racine
- Date:
- 2026-07-14 18:53:05 UTC
- Severity:
- normal
- Tags:
[ Reason ]
Backporting a fix for one minor CVE reported on the Debian security tracker.
CVE-2026-14258 was fixed in 10.2.0 (Sid has 10.3.2) but never backported until now.
[ Impact ]
Without it, successful exploitation of the CVE may result in excessive CPU consumption, leading to a denial of service.
[ Tests ]
Verified to boot on a host running Trixie.
[ Risks ]
Small. A few lines of code.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable
[ Changes ]
dhcpcd (1:10.1.0-11+deb13u4) trixie; urgency=medium
.
* [patches]
+ Cherry-pick upstream fix for CVE-2026-14258 (commit 75289ca).
= Refresh all patches.
package release.debian.org tags 1142049 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: dhcpcd Version: 10.1.0-11+deb13u4 Explanation: fix IPv6 Neighbor Discovery option parsing to discard advertisements with zero-length options [CVE-2026-14258]
package release.debian.org tags 1142049 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: dhcpcd Version: 10.1.0-11+deb13u4 Explanation: fix IPv6 Neighbor Discovery option parsing to discard advertisements with zero-length options [CVE-2026-14258]