CVE-2026-56115: Protocol Undimensioned Stack Buffer Dhcpv6

A 16-byte buffer is allocated for a DHCPv6 prefix exclude option (RFC 6603) that can occupy up to 17 bytes. This enables a one-byte stack buffer overflow.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2026-56115-protocol-undimensioned-stack-buffer-dhcpv6 --engine opengrep

Description

A 16-byte buffer is allocated for a DHCPv6 prefix exclude option (RFC 6603) that can occupy up to 17 bytes. This enables a one-byte stack buffer overflow.