← Back to CVE search

CVE-2026-41285

OpenBSD

Description

In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an -nd_opt_len * 8 - 2- expression with no preceding check for whether nd_opt_len is zero.

CVSS 4.3EPSS 0.209%Risk 0.44
View source
Published
2026-04-21 00:16:29
Affected versions
<7.8
Type
Core software
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L