CVE-2022-2929

MEDIUM

ISC Dhcp < 4.1-esv - Resource Allocation Without Limits

Title source: rule

Description

In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 16.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-770
Status published

Affected Products (34)

isc/dhcp < 4.1-esv
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
... and 19 more

Timeline

Published Oct 07, 2022
Tracked Since Feb 18, 2026