CVE-2016-2774: Input Validation
ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing many sessions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2774?
CVE-2016-2774 has a high severity rating as it allows remote attackers to cause a denial of service by overwhelming the DHCP server.
How do I fix CVE-2016-2774?
To fix CVE-2016-2774, upgrade to ISC DHCP versions 4.1-ESV-R13 or later, or 4.3.4 or later.
What versions are affected by CVE-2016-2774?
CVE-2016-2774 affects ISC DHCP versions 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4.
What impact can CVE-2016-2774 have on my network?
CVE-2016-2774 can result in system crashes and request-processing outages, significantly disrupting network services.
Is there a workaround for CVE-2016-2774?
Currently, there are no known workarounds for CVE-2016-2774; upgrading to a secure version is the only mitigation.