CVE-2022-2929: DHCP memory leak
In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-2929?
CVE-2022-2929 is a vulnerability in ISC DHCP that could allow an attacker to cause the DHCP server to run out of memory.
Which versions of ISC DHCP are affected by CVE-2022-2929?
ISC DHCP versions 1.0 to 4.4.3 and 4.1-ESV-R1 to 4.1-ESV-R16-P1 are affected by CVE-2022-2929.
What is the severity of CVE-2022-2929?
CVE-2022-2929 has a severity score of 6.5, which is considered medium.
How can CVE-2022-2929 be fixed?
To fix CVE-2022-2929, it is recommended to update to a patched version of ISC DHCP.
Where can I find more information about CVE-2022-2929?
More information about CVE-2022-2929 can be found in the references provided: [reference 1](https://kb.isc.org/docs/cve-2022-2929), [reference 2](https://lists.debian.org/debian-lts-announce/2022/10/msg00015.html), [reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/)