CVE-2026-53922 is a moderate-severity vulnerability in OpenWrt's odhcpd affecting DHCPv6 Identity Association handling. The flaw is described as a size_t underflow in the DHCPv6 IA processing path, reachable before authentication by a network-adjacent attacker sending crafted DHCPv6 traffic. The vulnerable condition occurs while parsing or handling DHCPv6 IA-related data, where insufficient bounds validation allows an unsigned size calculation to wrap, leading to invalid memory access during request processing. OpenWrt addressed the issue in an odhcpd update that also incorporated additional DHCPv6 input-validation and bounds-checking hardening.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A moderate pre-auth denial-of-service vulnerability in OpenWrt odhcpd caused by a size_t underflow in DHCPv6 IA handling.
A specific vulnerability in odhcpd addressed in OpenWrt openwrt-25.12 with multiple DHCP-related validation and safety fixes; the content does not map the CVE to one exact sub-bug.
A moderate pre-auth denial-of-service vulnerability in odhcpd caused by a size_t underflow in DHCPv6 IA handling.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.