6.5

CVE-2022-2929

DHCP memory leak

In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Isc ≫ Dhcp Version >= 1.0.0 < 4.1-esv
Isc ≫ Dhcp Version >= 4.2.0 <= 4.4.3
Isc ≫ Dhcp Version 4.1-esv Update r1
Isc ≫ Dhcp Version 4.1-esv Update r10
Isc ≫ Dhcp Version 4.1-esv Update r10_b1
Isc ≫ Dhcp Version 4.1-esv Update r10_rc1
Isc ≫ Dhcp Version 4.1-esv Update r10b1
Isc ≫ Dhcp Version 4.1-esv Update r10rc1
Isc ≫ Dhcp Version 4.1-esv Update r11
Isc ≫ Dhcp Version 4.1-esv Update r11_b1
Isc ≫ Dhcp Version 4.1-esv Update r11_rc1
Isc ≫ Dhcp Version 4.1-esv Update r11_rc2
Isc ≫ Dhcp Version 4.1-esv Update r11b1
Isc ≫ Dhcp Version 4.1-esv Update r11rc1
Isc ≫ Dhcp Version 4.1-esv Update r11rc2
Isc ≫ Dhcp Version 4.1-esv Update r12
Isc ≫ Dhcp Version 4.1-esv Update r12-p1
Isc ≫ Dhcp Version 4.1-esv Update r12_b1
Isc ≫ Dhcp Version 4.1-esv Update r12_p1
Isc ≫ Dhcp Version 4.1-esv Update r12b1
Isc ≫ Dhcp Version 4.1-esv Update r13
Isc ≫ Dhcp Version 4.1-esv Update r13_b1
Isc ≫ Dhcp Version 4.1-esv Update r13b1
Isc ≫ Dhcp Version 4.1-esv Update r14
Isc ≫ Dhcp Version 4.1-esv Update r14_b1
Isc ≫ Dhcp Version 4.1-esv Update r14b1
Isc ≫ Dhcp Version 4.1-esv Update r15
Isc ≫ Dhcp Version 4.1-esv Update r15-p1
Isc ≫ Dhcp Version 4.1-esv Update r15_b1
Isc ≫ Dhcp Version 4.1-esv Update r16
Isc ≫ Dhcp Version 4.1-esv Update r16-p1
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 35
Fedoraproject ≫ Fedora Version 36
Fedoraproject ≫ Fedora Version 37
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.64% 0.465
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
ISC 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://security.gentoo.org/glsa/202305-22
https://lists.debian.org/debian-lts-announce/2022/10/msg00015.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/
https://kb.isc.org/docs/cve-2022-2929
Vendor Advisory