CVE-2020-7216: High severity openSUSE wicked vulnerability
Published Feb 5, 2020
·Updated
An nidhcp4parseresponse memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets without a message type option.
Affected Software
2 affected components
openSUSE wicked<=0.6.55
openSUSE Leap=15.1
Event History
Feb 5, 2020
CVE Published
via MITRE·02:34 PM
Data Sourced
via MITRE·02:34 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-7216?
CVE-2020-7216 has a moderate severity level as it can lead to denial of service through memory leaks.
2
How do I fix CVE-2020-7216?
To fix CVE-2020-7216, update openSUSE wicked to version 0.6.56 or later.
3
Which software is affected by CVE-2020-7216?
CVE-2020-7216 affects openSUSE wicked versions 0.6.55 and earlier, as well as SUSE openSUSE Leap 15.1.
4
What type of attack does CVE-2020-7216 facilitate?
CVE-2020-7216 allows network attackers to execute a denial of service attack by sending specifically crafted DHCP4 packets.
5
Is there a workaround for CVE-2020-7216 if I cannot update?
While no official workaround is provided for CVE-2020-7216, consider restricting DHCP traffic to minimize exposure.