Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.
https://lists.suse.com/pipermail/sle-security-updates/2026-June/026691.html
https://lists.suse.com/pipermail/sle-security-updates/2026-June/026690.html
https://lists.suse.com/pipermail/sle-security-updates/2026-June/026689.html
https://lists.suse.com/pipermail/sle-security-updates/2026-June/026688.html