CVE-2022-2929

MEDIUM

ISC DHCP 1.0-4.4.3 and 4.1-ESV-R1-4.1-ESV-R16-P1 - Denial of Service via Oversized FQDN Labels

Title source: llm
STIX 2.1

Description

In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.

Scores

CVSS v3 6.5
EPSS 0.0008
EPSS Percentile 24.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-770
Status published
Products (6)
debian/debian_linux 10.0
fedoraproject/fedora 35
fedoraproject/fedora 36
fedoraproject/fedora 37
isc/dhcp 4.1-esv r1 (29 CPE variants)
isc/dhcp 1.0.0 - 4.1-esv
Published Oct 07, 2022
Tracked Since Feb 18, 2026