Impact
An integer underflow in the DHCPv4 packet capture routine of wicked allows an unauthenticated attacker on the same local network to trigger an out-of-bounds read. The code fails to verify that the total IP length field is at least as large as the IP header length before subtracting the header length, leading to a read beyond the receive buffer. This can cause the wicked DHCPv4 client daemon (wickedd-dhcp4) to crash, disrupting network connectivity for machines that rely on wicked for DHCP handling. No information disclosure was demonstrated in the available data.
Affected Systems
The vulnerability affects the SUSE wicked networking utility, specifically the DHCPv4 client component, up to and including version 0.6.80. Any deployment of wicked DHCPv4 in that version range is susceptible to exploitation.
Risk and Exploitability
The CVSS score of 5.3 represents a medium severity risk, and the exploit is feasible from any device on the same local network without authentication. Because the attack depends only on manipulating DHCP traffic, an attacker with local network access can trigger the out-of-bounds read, potentially causing a denial of service. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog. As a result, the likelihood of exploitation is uncertain, but the potential impact justifies proactive mitigation.
OpenCVE Enrichment