CVE-2022-2928: An option refcount overflow exists in dhcpd

Published Oct 7, 2022
·
Updated

In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function optioncodehashlookup() is called from addoption(), it increases the option's refcount field. However, there is not a corresponding call to optiondereference() to decrement the refcount field. The function addoption() is only used in server responses to lease query packets. Each lease query response calls this function for several options, so eventually, the reference counters could overflow and cause the server to abort.

Affected Software

34 affected components
ISC DHCP>=4.4.0<=4.4.3
ISC DHCP=4.1-esv-r1
ISC DHCP=4.1-esv-r10
ISC DHCP=4.1-esv-r10_b1
ISC DHCP=4.1-esv-r10_rc1
ISC DHCP=4.1-esv-r10b1
ISC DHCP=4.1-esv-r10rc1
ISC DHCP=4.1-esv-r11
ISC DHCP=4.1-esv-r11_b1
ISC DHCP=4.1-esv-r11_rc1
ISC DHCP=4.1-esv-r11_rc2
ISC DHCP=4.1-esv-r11b1
ISC DHCP=4.1-esv-r11rc1
ISC DHCP=4.1-esv-r11rc2
ISC DHCP=4.1-esv-r12
ISC DHCP=4.1-esv-r12-p1
ISC DHCP=4.1-esv-r12_b1
ISC DHCP=4.1-esv-r12_p1
ISC DHCP=4.1-esv-r12b1
ISC DHCP=4.1-esv-r13
ISC DHCP=4.1-esv-r13_b1
ISC DHCP=4.1-esv-r13b1
ISC DHCP=4.1-esv-r14
ISC DHCP=4.1-esv-r14_b1
ISC DHCP=4.1-esv-r14b1
ISC DHCP=4.1-esv-r15
ISC DHCP=4.1-esv-r15-p1
ISC DHCP=4.1-esv-r15_b1
ISC DHCP=4.1-esv-r16
ISC DHCP=4.1-esv-r16-p1
Debian Debian Linux=10.0
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Fedoraproject Fedora=37

Remediation

Information

Upgrade to the patched release most closely related to your current version of ISC DHCP. These can all be downloaded from https://www.isc.org/downloads. 4.4.3-P1 4.1-ESV-R16-P2

Event History

Oct 7, 2022
CVE Published
via MITRE·04:45 AM
Data Sourced
via MITRE·04:45 AM
RemedyDescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-2928?

The severity of CVE-2022-2928 is medium.

2

What is the affected software of CVE-2022-2928?

The affected software of CVE-2022-2928 is ISC DHCP versions 4.4.0 to 4.4.3 and 4.1-ESV-R1 to 4.1-ESV-R16-P1.

3

How does CVE-2022-2928 impact ISC DHCP?

CVE-2022-2928 increases the option's refcount field, but does not decrement it, leading to a vulnerability.

4

How can I fix CVE-2022-2928?

To fix CVE-2022-2928, upgrade to a version of ISC DHCP that is not affected.

5

Where can I find more information about CVE-2022-2928?

More information about CVE-2022-2928 can be found in the references provided.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203