CVE-2026-42511Disclosure(freebsd / freebsd)

MEDIUMCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch freebsd freebsd systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhclient-script(8), which evaluates it. A rogue DHCP server may be able to execute arbirary code as root on a system running dhclient.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-149

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freebsd

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 27 mentions across 9 observed days
  • Momentum state: declining

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 23 signals
  • Disclosure: 16 classified signals
  • General: 2 classified signals
  • Peaked 7d ago at 14 mentions (2026-05-04); latest day: 1
  • 27 total mentions across 9 days

Affected systems

Vendors
Products
freebsd

4 versions affected across 1 product

Deep dive

Activity timeline27 mentions / 9d
0471114Mentions · 2026-04-30: 1Mentions · 2026-05-04: 14Mentions · 2026-05-05: 2Mentions · 2026-05-06: 2Mentions · 2026-05-08: 3Mentions · 2026-05-11: 1Mentions · 2026-05-19: 1Mentions · 2026-05-20: 2Mentions · 2026-06-06: 1PoC Mentioned / Linked · 2026-05-04: 2PoC Mentioned / Linked · 2026-05-08: 1Exploit Tool / Code · 2026-05-04: 1Exploit Tool / Code · 2026-05-08: 1Patch / Workaround · 2026-05-04: 6Patch / Workaround · 2026-05-05: 1Technical Details · 2026-05-04: 12Technical Details · 2026-05-05: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-08: 3Technical Details · 2026-05-11: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-20: 2Technical Details · 2026-06-06: 104-3005-0405-0505-0605-0805-1105-1905-2006-06
Signal classification5 categories
Disclosure
1659.3%
Patch
725.9%
General
27.4%
PoC
13.7%
Exploit
13.7%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-04-301
General1
2026-05-0414
Disclosure6General1Patch6PoC1
2026-05-052
Disclosure1Patch1
2026-05-062
Disclosure2
2026-05-083
Disclosure2Exploit1
2026-05-111
Disclosure1
2026-05-191
Disclosure1
2026-05-202
Disclosure2
2026-06-061
Disclosure1
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Disclosure

    ⚠️ FreeBSD DHCP Client Vulnerability Enables Remote Code Execution as Root Source: https://cybersecuritynews.com/freebsd-dhcp-client-vulnerability/ The FreeBSD Project has released a critical security advisory addressing a severe flaw in its default IPv4 DHCP client. Tracked as CVE-2026-42511, this vulnerability allows a local network attacker to execute arbitrary code as root, granting them complete control over the compromised machine. The core issue resides in how dhclient(8) processes network configuration parameters from DHCP servers. When a device joins a network, it requests IP configuration data. The DHCP client takes the provided BOOTP file field and writes it to a local DHCP lease file. #cybersecuritynews

    Post summary

    FreeBSD’s default DHCP client is vulnerable to a critical flaw that allows local attackers to achieve root-level code execution, and the project has issued an advisory detailing the issue.

    101191740212482.0K
    67.1K followersView on X
  • Stanislav Fort@stanislavfort
    Disclosure

    This one is ours! CVE-2026-42511 was discovered by Joshua Rogers from our research team using @Aisle_Inc's AI system in FreeBSD, the same codebase Anthropic previously scanned with Mythos. Remote code execution as root in FreeBSD's DHCP client, affecting all supported versions!

    Post summary

    A research team announces discovery of CVE-2026‑42511, a root‑level remote code execution flaw in FreeBSD's DHCP client that affects all supported versions.

    55112619344.0K
    16.7K followersView on X
  • dbugs@ptdbugs
    Disclosure

    21-year-old RCE vulnerability in FreeBSD (CVE-2026-42511) PT ID: PT-2026-36009 The article describes the critical vulnerability CVE-2026-42511 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-42511) in the FreeBSD DHCP client ("dhclient"), which existed for more than 20 years and allowed arbitrary code execution with "root" privileges. The issue lies in the fact that the BOOTP "file" field is written into the lease file without proper escaping; later, during reprocessing, this file is interpreted as a configuration and passed to "dhclient-script", where it can be executed as malicious code. An attacker only needs to control the DHCP server on the same network (for example, via a rogue Wi-Fi access point or DHCP response spoofing) to inject malicious instructions and achieve full system compromise. 📎 Article: https://aisle.com/blog/aisle-discovers-cve-2026-42511-a-21-year-old-freebsd-remote-command-execution-vulnerability#the-vulnerability #dbugs_attacks

    Post summary

    The article discloses a 21‑year‑old RCE in FreeBSD’s dhclient, detailing how an unescaped BOOTP "file" field can lead to root‑level code execution, but provides no PoC, exploit, or patch information.

    110039113.0K
    2.6K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-42511 Breakdown: RCE in FreeBSD https://aisle.com/blog/aisle-discovers-cve-2026-42511-a-21-year-old-freebsd-remote-command-execution-vulnerability#the-vulnerability

    Post summary

    The post announces a newly disclosed RCE vulnerability (CVE-2026-42511) affecting FreeBSD, linking to a blog for details, but offers no PoC, exploitation evidence, or patch information.

    030851.6K
    158.1K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    FreeBSD warns of CVE-2026-42511: a critical dhclient flaw allowing rogue DHCP servers to execute code as root via BOOTP file injection. Patch and reboot now! #FreeBSD #CyberSecurity #InfoSec #DHCP #RootExploit #CVE202642511 #SysAdmin #NetSec https://securityonline.info/freebsd-dhclient-root-vulnerability-cve-2026-42511/ https://t.co/OjDOQM8qYP

    Post summary

    FreeBSD releases a critical advisory for CVE‑2026‑42511, detailing a dhclient flaw that permits root code execution via BOOTP injection and urging users to apply the patch and reboot.

    2201111.3K
    12.5K followersView on X
  • Grok@grok
    Disclosure

    @robinvwb @The_Cyber_News Yes, it was discovered by Joshua Rogers of the AISLE Research Team. They specialize in using AI models to scan codebases for vulnerabilities like this one (CVE-2026-42511) in FreeBSD's dhclient. The FreeBSD advisory credits him directly.

    Post summary

    The tweet simply confirms that CVE‑2026‑42511 was discovered by Joshua Rogers for FreeBSD’s dhclient, with no further technical, exploit, or patch details provided.

    00042309
    8.7M followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    FreeBSD DHCP Client Vulnerability Enables Remote Code Execution as Root https://cybersecuritynews.com/freebsd-dhcp-client-vulnerability/ "Tracked as CVE-2026-42511, this vulnerability allows a local network attacker to execute arbitrary code as root,…" https://t.co/52U8yDKqyZ

    Post summary

    The text announces a new FreeBSD DHCP client vulnerability (CVE-2026-42511) that allows local network attackers to execute code as root, with no PoC or active exploitation details disclosed.

    11011250
    3.5K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 ثغرة في عميل DHCP في نظام FreeBSD تسمح بتنفيذ كود عن بعد بامتيازات الجذر تم الإبلاغ عن وجود ثغرة أمنية خطيرة في عميل DHCP الافتراضي لنظام FreeBSD، والذي يحمل الرقم CVE-2026-42511 ودرجة CVSS تبلغ 8.1. تسمح هذه الثغرة بتنفيذ كود عن بعد بامتيازات الجذر. يرجع سبب هذه الثغرة إلى عدم كفاية التحقق من صحة المدخلات في عميل DHCP. تأثرت أنظمة FreeBSD بهذه الثغرة، ويُنصح بتحديث الإصدارات المتأثرة على الفور. — يُنصح بـ تحديث الإصدارات المتأثرة واتباع الإرشادات الأمنية لشركة FreeBSD. 🔗 للمزيد: https://securityonline.info/freebsd-dhclient-root-vulnerability-cve-2026-42511/

    Post summary

    The post announces a new high‑severity FreeBSD DHCP client vulnerability (CVE‑2026‑42511) and advises immediate patching, without providing exploit code or evidence of exploitation.

    00030721
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    AISLE's Findings: CVE-2026-42511 (CVSS 9.1) – Remote Code Execution in dhclient The DHCP client writes BOOTP fields directly to the lease file without escaping double-quotes Allows injection of arbitrary dhclient.conf directives Upon system restart, attacker-controlled…

    Post summary

    AISLE uncovered a high‑severity CVE-2026-42511 in dhclient, where unescaped BOOTP fields allow injection of arbitrary configuration directives, leading to remote code execution upon system restart. No PoC, exploit tool, or patch details are provided.

    1000027
    247 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Vendor. 0day Intel: 21-year-old RCE vulnerability in FreeBSD (CVE-2026-42511)

    Post summary

    The text announces a 21‑year‑old remote code execution flaw in FreeBSD (CVE‑2026‑42511) but provides no PoC, exploit details, or patch information.

    1000065
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42511. 0day Intel: 21-year-old RCE vulnerability in FreeBSD (CVE-2026-42511)

    Post summary

    A brief notice announcing the discovery of a 21‑year‑old remote code‑execution vulnerability (CVE‑2026‑42511) in FreeBSD, without providing exploit, patch, or detailed technical information.

    1000066
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42511: ⚠️ FreeBSD DHCP Client Vulnerability Enables Remote Code Execution as Root Source: The FreeBSD Project has released a critical security advisory addressing a severe flaw in its default IPv4 DHCP client. Tracked as CVE-2026-42511,…

    Post summary

    The advisory announces a critical RCE vulnerability (CVE‑2026‑42511) in FreeBSD’s IPv4 DHCP client but does not provide PoC, exploit code, active exploitation evidence, or patch details.

    1000051
    155 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The FreeBSD Project has released a critical security advisory addressing a severe flaw in its default IPv4 DHCP client. Tracked as CVE-2026-42511, this vulnerability

    Post summary

    The statement declares a critical advisory for CVE-2026-42511 affecting FreeBSD's default IPv4 DHCP client, but provides no further technical, exploit, or mitigation details.

    1000039
    155 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical #FreeBSD vulnerability (CVE-2026-42511) A flaw in the default IPv4 DHCP client (dhclient) allows a local network attacker to execute arbitrary code as root - full system compromise. The issue stems from unsafe handling of DHCP parameters written to the lease file. Patch ASAP.

    Post summary

    A local privilege‑escapable flaw in FreeBSD’s dhclient (CVE‑2026‑42511) is highlighted, with an urgent patch called for.

    00010121
    122 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    FreeBSD DHCP クライアントの脆弱性 CVE-2026-42511 が FIX:root 権限での任意のコード実行 https://iototsecnews.jp/2026/05/04/freebsd-dhcp-client-vulnerability-enables-remote-code-execution-as-root/ FreeBSD の脆弱性 CVE-2026-42511 は、dhclient が外部からのデータを処理する際の、情報整理の不備が大きな原因となっています。本来、サーバから送られてくる文字列にダブル・クォートなどの特別な記号が含まれている場合には、それらを無害な文字として扱う “エスケープ処理” を行う必要がありますが、今回はその処理が不足していました。そのため、攻撃者が用意した悪意の命令が、そのまま設定ファイルの一部として取り込まれてしまいます。ご利用のチームは、ご注意ください。 #CVE202642511 #FreeBSD #Vulnerability

    Post summary

    The post discloses a CVE-2026-42511 vulnerability in FreeBSD's DHCP client, detailing how inadequate escape handling leads to root-level code execution, but it offers no PoC, exploit, or patch information.

    00000188
    491 followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit 1⃣. CVE-2026-42511: A 21-Year-Old FreeBSD RCE Vulnerability https://aisle.com/blog/aisle-discovers-cve-2026-42511-a-21-year-old-freebsd-remote-command-execution-vulnerability // Any attacker able to operate a malicious DHCP server on the same broadcast domain, or spoof one, can feed hostile lease data to the client.. 2⃣. VLC Media Player MKV Exploit Analysis https://www.eshard.com/blog/vlc-media-player-mkv-exploit-analysis // This post is part of a series on MCP-based time-travel debugging for security analysis 3⃣. Dirty Frag: https://github.com/V4bel/dirtyfrag#dirty-frag-universal-linux-lpe 0-day Universal Linux LPE // Dirty Frag is a case that extends the bug class to which Dirty Pipe https://dirtypipe.cm4all.com/ and https://copy.fail/ Copy Fail belong

    Post summary

    The post lists multiple vulnerabilities, providing links to PoC repositories and describing RCE/LPE mechanisms, indicating that functional exploit code is available but no evidence of active exploitation or patches.

    00000248
    3.3K followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    Disclosure

    اكتشاف ثغرة CVE-2026-42511: تنفيذ أوامر عن بُعد في نظام FreeBSD Understanding CVE-2026-42511: This Remote Code Execution vulnerability in FreeBSD could have significant security implications. Explore the details and potential impacts. https://aisle.com/blog/aisle-discovers-cve-2026-42511-a-21-year-old-freebsd-remote-command-execution-vulnerability#the-vulnerability #Cybersecurity #FreeBSD #VulnerabilityAnalysis

    Post summary

    The post announces the discovery of CVE‑2026‑42511, a Remote Command Execution flaw in FreeBSD, but offers no details on patches, PoCs, or active exploitation.

    0000056
    63 followersView on X
  • Mashari-PHD@GMashari
    Patch

    📌 ثغرة في عميل DHCP في نظام FreeBSD تسمح بتنفيذ كود عن بعد بامتيازات الجذر 🛡️ الفئة: ثغرة 📝 الملخص: تم الإبلاغ عن وجود ثغرة أمنية خطيرة في عميل DHCP الافتراضي لنظام FreeBSD، والذي يحمل الرقم CVE-2026-42511 ودرجة CVSS تبلغ 8.1. تسمح هذه الثغرة بتنفيذ كود عن بعد بامتيازات الجذر. يرجع سبب هذه الثغرة إلى عدم كفاية التحقق من صحة المدخلات في عميل DHCP. تأثرت أنظمة FreeBSD بهذه الثغرة، ويُنصح بتحديث الإصدارات المتأثرة على الفور. — يُنصح بـ تحديث الإصدارات المتأثرة واتباع الإرشادات الأمنية لشركة FreeBSD. 🗓️ تاريخ النشر: 04/05/2026 🔗 للمزيد: https://securityonline.info/freebsd-dhclient-root-vulnerability-cve-2026-42511/

    Post summary

    The post announces a CVSS‑8.1 remote‑code‑execution vulnerability (CVE-2026‑42511) in FreeBSD’s DHCP client and urges users to patch affected versions immediately.

    0000096
    8.9K followersView on X
  • Syndicate Cybersecurity@syn_sec
    Disclosure

    CVE-2026-42511: FreeBSD dhclient Remote Code Execution via DHCP https://syndicatesec.com/blog/cve-2026-42511-freebsd-dhclient-rce.html

    Post summary

    The snippet announces CVE-2026-42511, a remote code execution flaw in FreeBSD's dhclient triggered through DHCP. No PoC, exploit code, active use, or patch details are disclosed in the text.

    0000084
    4 followersView on X
  • Grok@grok
    General

    No, this FreeBSD dhclient vuln (CVE-2026-42511) doesn't impact Darwin/macOS. Apple uses its own DHCP client (via configd/SystemConfiguration), not FreeBSD's. Darwin draws heavily from FreeBSD userland (4.4BSD lineage) plus some NetBSD bits, but the kernel is XNU (Mach-based) and networking tools diverged long ago. FreeBSD systems on DHCP are the ones at risk here.

    Post summary

    The post corrects a misconception, stating that CVE-2026-42511, a FreeBSD dhclient vulnerability, does not affect Darwin/macOS and is limited to FreeBSD systems.

    0000081
    8.7M followersView on X
CPE platform detail37 entries

37 of 37 entries

PartVendorProductVersionTarget SWTarget HW
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--

Explore more