The FreeBSD Project disclosed CVE-2026-42511, a critical vulnerability in the default IPv4 DHCP client, dhclient(8), that can allow a local network attacker to execute arbitrary code as root. The flaw arises because dhclient(8) does not properly escape double quotes in the BOOTP file field before writing data to the DHCP lease file, allowing a malicious DHCP response to inject configuration content that is later re-parsed and executed by dhclient-script(8).
Exploitation requires the attacker to be on the same broadcast domain and operate a rogue DHCP server that replies with crafted DHCP data. FreeBSD said the issue affects all currently supported branches, including FreeBSD 15.0, 14.4, 14.3, and 13.5 release and stable versions, and published patches in security advisory FreeBSD-SA-26:12.dhclient. Administrators were urged to update immediately, and FreeBSD noted that switch-level DHCP snooping can help mitigate attacks from rogue DHCP servers where continued use of dhclient is necessary.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-29, FreeBSD published advisories for two additional vulnerabilities credited to AISLE researcher Joshua Rogers: CVE-2026-42512, a remotely triggerable dhclient heap buffer overrun, and CVE-2026-39457, a libnv stack overflow that can enable local privilege escalation through a privileged consumer.
FreeBSD released fixes for supported versions including 15.0, 14.4, 14.3, and 13.5 release and stable branches, and urged administrators to update. The project also noted DHCP snooping on switches as a mitigation where dhclient must remain in use.
The FreeBSD Project issued security advisory FreeBSD-SA-26:12 for CVE-2026-42511, a remote code execution flaw in the default IPv4 DHCP client. The bug allows a local network attacker operating a rogue DHCP server on the same broadcast domain to inject malicious configuration that can later be executed as root by dhclient-script(8).
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcefreebsd.org
Open sourcebugflation.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.