CVE-2026-44932: Suse Wicked

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.

Affected products

  • Suse Wicked: before 0.6.79 (fixed in 0.6.79)

Published 2026-06-16. Last modified 2026-06-18.