CVE-2026-42512General(freebsd / freebsd)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrectly calculates its new size when requesting memory, resulting in a heap buffer overrun. A specially crafted packet can cause dhclient to overrun its buffer of environment entries. This can result in a crash, but it may be possible to leverage this bug to achieve remote code execution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freebsd

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-30); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
freebsd

4 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-30: 2Mentions · 2026-05-09: 1Mentions · 2026-06-06: 1Technical Details · 2026-04-30: 1Technical Details · 2026-06-06: 104-3005-0906-06
Signal classification2 categories
General
375.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-302
General2
2026-05-091
General1
2026-06-061
Disclosure1
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42512 (CVSS 8.6) – Heap Buffer Overrun in dhclient Array resizing logic in environment variable construction miscalculates new size Specially crafted DHCP packets trigger out-of-bounds write Remotely triggerable, potentially exploitable for code execution

    Post summary

    The text announces a new heap buffer overrun vulnerability (CVE‑2026‑42512) in dhclient, providing technical details but no evidence of a PoC, exploit code, active exploitation, or patch.

    1000047
    247 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-42512: FreeBSD dhclient Heap Buffer Overflow - What It Means for Your Business and How to Respond https://hubs.li/Q04g0PmX0

    Post summary

    The text informs of a FreeBSD dhclient heap buffer overflow CVE and hints at a business impact analysis, but provides no concrete technical, exploit, or mitigation details.

    0000035
    30 followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting FreeBSD (CVE-2026-42512) https://vuldb.com/vuln/360259

    Post summary

    The note announces that the severity of the new FreeBSD vulnerability CVE-2026-42512 has been increased, but offers no details on exploitation, patches, or technical specifics.

    0000047
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42512 Heap Buffer Overrun in dhclient Environment Array Resizing via Cr... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42512 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet references CVE-2026-42512, identifies a heap buffer overrun in dhclient, but provides no PoC, exploit details, patch information, or evidence of active exploitation.

    0000019
    4.0K followersView on X
CPE platform detail37 entries

37 of 37 entries

PartVendorProductVersionTarget SWTarget HW
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--

Explore more