CVE-2026-48715Disclosure(radvd.litech / radvd)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, `print_ff()` copies up to 2032 bytes from attacker-controlled packet data into a 16-byte `struct in6_addr` on the stack, overflowing by up to 2016 bytes. Note that the main `radvd` daemon is not affected by the vulnerability. Version 2.21 patches the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • radvd

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-19); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
radvd

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-19: 2Mentions · 2026-06-20: 1Technical Details · 2026-06-19: 2Technical Details · 2026-06-20: 106-1906-20
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-192
Disclosure2
2026-06-201
Disclosure1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-48715 radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Inform… https://www.cve.org/CVERecord?id=CVE-2026-48715 ----- Traducción: CVE-2026-48715 rad… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-48715, describing a stack buffer overflow in radvd's radvdump utility prior to version 2.21 and linking to the official CVE record.

    0001051
    82 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-48715 Stack Buffer Overflow in radvd radvdump Route Information Option Parser https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-48715

    Post summary

    A brief disclosure of CVE-2026-48715, describing a stack buffer overflow in radvd radvdump's route option parser, with a link to a Vulmon details page.

    0000080
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-48715 radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Inform… https://www.cve.org/CVERecord?id=CVE-2026-48715

    Post summary

    The post announces the discovery of a stack buffer overflow in radvd's radvdump utility, providing technical details but no PoC, exploit, or patch information.

    00000329
    57.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appradvd.litechradvd---

Explore more