CVE-2022-2929
Published: 5 October 2022
In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.
Priority
Status
Package | Release | Status |
---|---|---|
isc-dhcp Launchpad, Ubuntu, Debian |
bionic |
Released
(4.3.5-3ubuntu7.4)
|
focal |
Released
(4.4.1-2.1ubuntu5.20.04.4)
|
|
jammy |
Released
(4.4.1-2.3ubuntu2.3)
|
|
kinetic |
Released
(4.4.3-2ubuntu4)
|
|
upstream |
Released
(4.4.3-P1,4.1-ESV-R16-P2)
|
|
xenial |
Released
(4.3.3-5ubuntu12.10+esm2)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
|
trusty |
Released
(4.2.4-7ubuntu12.13+esm2)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.5 |
Attack vector | Adjacent |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2929
- https://lists.isc.org/pipermail/dhcp-announce/2022-October/000437.html
- https://kb.isc.org/docs/cve-2022-2929
- https://ubuntu.com/security/notices/USN-5658-1
- https://ubuntu.com/security/notices/USN-5658-2
- https://ubuntu.com/security/notices/USN-5658-3
- NVD
- Launchpad
- Debian