DHCP memory leak
CVE-2022-2929

6.5MEDIUM

Key Information:

Vendor
Isc
Status
Vendor
CVE Published:
7 October 2022

Badges

👾 Exploit Exists

Summary

In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.

Affected Version(s)

ISC DHCP 1.0 through versions before 4.1-ESV-R16-P2

ISC DHCP 4.2 through versions before 4.4.3.-P1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

ISC would like to thank VictorV of Cyber Kunlun Lab for discovering and reporting this issue.
.