CVE-2022-2929
MEDIUMISC Dhcp < 4.1-esv - Resource Allocation Without Limits
Title source: ruleDescription
In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.
References (6)
Scores
CVSS v3
6.5
EPSS
0.0005
EPSS Percentile
16.5%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-770
Status
published
Affected Products (34)
isc/dhcp
< 4.1-esv
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
isc/dhcp
... and 19 more
Timeline
Published
Oct 07, 2022
Tracked Since
Feb 18, 2026