CVE-2026-48715
radvdump's Route Information Option Parser has a Stack Buffer Overflow
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, `print_ff()` copies up to 2032 bytes from attacker-controlled packet data into a 16-byte `struct in6_addr` on the stack, overflowing by up to 2016 bytes. Note that the main `radvd` daemon is not affected by the vulnerability. Version 2.21 patches the issue.
| CWE | CWE-121 |
| Vendor | radvd-project |
| Product | radvdump |
| Published | Jun 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for radvd-project radvdump
Be the first to know when new unknown vulnerabilities affecting radvd-project radvdump are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
radvd-project / radvdump
< 2.21