CVE-2026-42511
The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhclient-script(8), which evaluates it. A rogue DHCP server may be able to execute arbirary code as root on a system running dhclient.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.43%
- CWE
- CWE-149
- Published
- 2026-04-30
- Last modified
- 2026-05-01
Affected products
- FreeBSD FreeBSD
- FreeBSD FreeBSD
- FreeBSD FreeBSD
- FreeBSD FreeBSD
Weakness type
Related vulnerabilities
- CVE-2018-25135 — Anviz AIM CrossChex Standard 4.3.6.0 CSV Injection via User Import
- CVE-2025-43878 — F5OS-A/C CLI vulnerability
- CVE-2025-1094 — PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
- CVE-2023-36479 — Jetty vulnerable to errant command quoting in CGI Servlet