engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertisement with more than seven nameservers. NOTE: privilege separation and pledge can prevent exploitation.
| Software | From | Fixed in |
|---|---|---|
| openbsd / openbsd | 7.0 | 7.0.x |
| openbsd / openbsd | 6.9 | 6.9.x |