{"document":{"aggregate_severity":{"namespace":"https://access.redhat.com/security/updates/classification/","text":"Moderate"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright © Red Hat, Inc. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"legal_disclaimer","text":"This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.","title":"Terms of Use"}],"publisher":{"category":"vendor","contact_details":"https://access.redhat.com/security/team/contact/","issuing_authority":"Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.","name":"Red Hat Product Security","namespace":"https://www.redhat.com"},"references":[{"category":"self","summary":"Canonical URL","url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-70102.json"}],"title":"dhcpcd: dhcpcd: Denial of Service via NULL pointer dereference during configuration option parsing","tracking":{"current_release_date":"2026-06-28T11:00:21+00:00","generator":{"date":"2026-06-28T11:00:21+00:00","engine":{"name":"Red Hat SDEngine","version":"5.2.6"}},"id":"CVE-2025-70102","initial_release_date":"2025-01-01T00:00:00+00:00","revision_history":[{"date":"2025-01-01T00:00:00+00:00","number":"1","summary":"Initial version"},{"date":"2026-06-22T13:01:21.082599+00:00","number":"2","summary":"Current version"},{"date":"2026-06-28T11:00:21+00:00","number":"3","summary":"Last generated version"}],"status":"final","version":"3"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"Red Hat Enterprise Linux 10","product":{"name":"Red Hat Enterprise Linux 10","product_id":"red_hat_enterprise_linux_10","product_identification_helper":{"cpe":"cpe:/o:redhat:enterprise_linux:10"}}}],"category":"product_family","name":"Red Hat Enterprise Linux 10"},{"category":"product_version","name":"dhcpcd.src","product":{"name":"dhcpcd.src","product_id":"dhcpcd.src","product_identification_helper":{"purl":"pkg:rpm/redhat/dhcpcd?arch=src"}}}],"category":"vendor","name":"Red Hat"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"dhcpcd.src as a component of Red Hat Enterprise Linux 10","product_id":"red_hat_enterprise_linux_10:dhcpcd.src"},"product_reference":"dhcpcd.src","relates_to_product_reference":"red_hat_enterprise_linux_10"}]},"vulnerabilities":[{"cve":"CVE-2025-70102","cwe":{"id":"CWE-476","name":"NULL Pointer Dereference"},"discovery_date":"2026-06-15T20:01:55.528935+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2488997"}],"notes":[{"category":"description","text":"A flaw was found in dhcpcd. A specially crafted configuration input may cause the parse_option() function to dereference a NULL pointer while processing malformed option data. This issue may result in application termination and a denial of service condition.","title":"Vulnerability description"},{"category":"summary","text":"dhcpcd: dhcpcd: Denial of Service via NULL pointer dereference during configuration option parsing","title":"Vulnerability summary"},{"category":"other","text":"This vulnerability affects dhcpcd's configuration parsing functionality. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability.\n\nThe flaw occurs in the parse_option() function when processing malformed configuration option data. Under certain conditions, an internal DHCP option structure may remain NULL while the code incorrectly assumes it has been initialized and subsequently dereferences it.\n\nPrivileges Required (PR:H): Exploitation requires the ability to supply or modify configuration data processed by dhcpcd. In typical deployments, modification of dhcpcd configuration files requires administrative privileges.\n\nSuccessful exploitation may cause dhcpcd to terminate unexpectedly, resulting in a denial of service condition.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"known_affected":["red_hat_enterprise_linux_10:dhcpcd.src"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2025-70102"},{"category":"external","summary":"RHBZ#2488997","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488997"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2025-70102","url":"https://www.cve.org/CVERecord?id=CVE-2025-70102"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2025-70102","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-70102"},{"category":"external","summary":"https://infosec.exchange/@sigdevel/116733594508542047","url":"https://infosec.exchange/@sigdevel/116733594508542047"}],"release_date":"2026-06-15T00:00:00+00:00","remediations":[{"category":"workaround","details":"Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.","product_ids":["red_hat_enterprise_linux_10:dhcpcd.src"]},{"category":"none_available","details":"Fix deferred","product_ids":["red_hat_enterprise_linux_10:dhcpcd.src"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":4.4,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["red_hat_enterprise_linux_10:dhcpcd.src"]}],"threats":[{"category":"impact","details":"Moderate","product_ids":["red_hat_enterprise_linux_10:dhcpcd.src"]}],"title":"dhcpcd: dhcpcd: Denial of Service via NULL pointer dereference during configuration option parsing"}]}