CVE-2017-3144: Failure to properly clean up closed OMAPI connections can exhaust available sockets

Published Dec 6, 2017
·
Updated

A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected but are well beyond their end-of-life (EOL). Releases prior to 4.1.0 have not been tested.

Other sources

It was found that omapi code doesn't free socket descriptor if empty message was sent by client, which allows malicious client to use up all available descriptors causing Denial of Service.

Upstream patch:

https://source.isc.org/cgi-bin/gitweb.cgi?p=dhcp.git;a=commit;h=1a6b62fe17a

Red Hat

Affected Software

53 affected componentsFixes available
debian/isc-dhcp<=4.2.2.dfsg.1-5+deb70u8, <=4.3.1-6
4.3.5-3.14.3.5-3+deb9u14.3.1-6+deb8u3
ISC DHCP>=4.2.0<=4.2.8
ISC DHCP>=4.3.0<=4.3.6
ISC DHCP=4.1-esv
ISC DHCP=4.1-esv-r1
ISC DHCP=4.1-esv-r10
ISC DHCP=4.1-esv-r10_b1
ISC DHCP=4.1-esv-r10_rc1
ISC DHCP=4.1-esv-r11
ISC DHCP=4.1-esv-r11_b1
ISC DHCP=4.1-esv-r11_rc1
ISC DHCP=4.1-esv-r11_rc2
ISC DHCP=4.1-esv-r12
ISC DHCP=4.1-esv-r12_b1
ISC DHCP=4.1-esv-r12_p1
ISC DHCP=4.1-esv-r13
ISC DHCP=4.1-esv-r13_b1
ISC DHCP=4.1-esv-r14
ISC DHCP=4.1-esv-r14_b1
ISC DHCP=4.1-esv-r15
ISC DHCP=4.1-esv-r2
ISC DHCP=4.1-esv-r3
ISC DHCP=4.1-esv-r3_b1
ISC DHCP=4.1-esv-r4
ISC DHCP=4.1-esv-r5
ISC DHCP=4.1-esv-r5_b1
ISC DHCP=4.1-esv-r5_rc1
ISC DHCP=4.1-esv-r5_rc2
ISC DHCP=4.1-esv-r6
ISC DHCP=4.1-esv-r7
ISC DHCP=4.1-esv-r8
ISC DHCP=4.1-esv-r8_b1
ISC DHCP=4.1-esv-r8_rc1
ISC DHCP=4.1-esv-r9
ISC DHCP=4.1-esv-r9_b1
ISC DHCP=4.1-esv-r9_rc1
ISC DHCP=4.1.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Eus=7.4
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Server Tus=7.4
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Workstation=7.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/isc-dhcp
4.4.1-2.3+deb11u24.4.1-2.3+deb11u14.4.3-P1-24.4.3-P1-8

Event History

Dec 6, 2017
Data Sourced
via Red Hat·05:52 PM
DescriptionSeverityAffected Software
Jan 16, 2019
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Jan 11, 2024
Data Sourced
via Launchpad·10:37 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·04:50 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:50 PM
DescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2017-3144?

CVE-2017-3144 is classified as a medium severity vulnerability due to its potential to exhaust socket descriptors.

2

How do I fix CVE-2017-3144?

To mitigate CVE-2017-3144, upgrade ISC DHCP to version 4.4 or later or apply vendor patches as specified.

3

What systems are affected by CVE-2017-3144?

CVE-2017-3144 affects ISC DHCP versions 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, and 4.3.0 to 4.3.6.

4

What causes CVE-2017-3144?

CVE-2017-3144 is caused by the failure to properly clean up closed OMAPI connections, leading to resource exhaustion.

5

Can older versions of ISC DHCP be impacted by CVE-2017-3144?

Yes, older versions of ISC DHCP may also be vulnerable to CVE-2017-3144, although they are not explicitly listed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203