A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.
https://usn.ubuntu.com/3807-1/
https://usn.ubuntu.com/3806-1/
https://security.gentoo.org/glsa/201810-10
https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html
https://github.com/systemd/systemd/pull/10518
https://access.redhat.com/errata/RHSA-2019:0049
https://access.redhat.com/errata/RHSA-2018:3665