CVE-2026-48715 PUBLISHED

radvdump's Route Information Option Parser has a Stack Buffer Overflow

Assigner: GitHub_M
Reserved: 22.05.2026 Published: 19.06.2026 Updated: 19.06.2026

radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the radvdump utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, print_ff() copies up to 2032 bytes from attacker-controlled packet data into a 16-byte struct in6_addr on the stack, overflowing by up to 2016 bytes. Note that the main radvd daemon is not affected by the vulnerability. Version 2.21 patches the issue.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.7

Product Status

Vendor radvd-project
Product radvdump
Versions
  • Version < 2.21 is affected

References

Problem Types

  • CWE-121: Stack-based Buffer Overflow CWE