CVE-2019-11766: Debian Linux

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Dhcpcd Project Dhcpcd: before 6.11.7 (fixed in 6.11.7); from 7.0.0, before 7.2.2 (fixed in 7.2.2)

Published 2019-05-05. Last modified 2026-06-17.