CVE-2026-48715

Name
CVE-2026-48715
Description
radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, `print_ff()` copies up to 2032 bytes from attacker-controlled packet data into a 16-byte `struct in6_addr` on the stack, overflowing by up to 2016 bytes. Note that the main `radvd` daemon is not affected by the vulnerability. Version 2.21 patches the issue.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/radvd-project/radvd/commit/068bde13e3fd6a5fcdb6859e6a2acd293a325dc5
security-advisories@github.com https://github.com/radvd-project/radvd/security/advisories/GHSA-52px-gh9p-m379

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:radvd.litech:radvd:*:*:*:*:*:*:*:* radvd >= None < 2.21

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
radvd edge-main 2.21-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
radvd edge-main 2.20-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
radvd edge-main 2.19-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
radvd 3.24-main 2.21-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
radvd 3.23-main 2.20-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
radvd 3.22-main 2.20-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
radvd 3.21-main 2.19-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
radvd 3.20-main 2.19-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
radvd 3.19-main 2.19-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable