CVE-2026-14258: Red Hat Enterprise Linux 10

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Advertisement containing a zero-length Neighbor Discovery option can bypass validation during packet storage and later be reparsed without adequate validation, causing the parser to enter a non-advancing loop. Successful exploitation may result in excessive CPU consumption, leading to a denial of service.

Affected products

  • Red Hat Red Hat Enterprise Linux 10: before 0:10.0.6-11.el10_2 (fixed in 0:10.0.6-11.el10_2)

Published 2026-07-01. Last modified 2026-08-12.