REDHAT-BUG-1522918: Medium severity isc dhcp client vulnerability
It was found that omapi code doesn't free socket descriptor if empty message was sent by client, which allows malicious client to use up all available descriptors causing Denial of Service.
Upstream patch:
https://source.isc.org/cgi-bin/gitweb.cgi?p=dhcp.git;a=commit;h=1a6b62fe17a
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1522918?
The severity of REDHAT-BUG-1522918 is high due to the potential for Denial of Service caused by the exhaustion of available socket descriptors.
How do I fix REDHAT-BUG-1522918?
To fix REDHAT-BUG-1522918, you should apply the upstream patch provided by ISC for the DHCP server.
What product is affected by REDHAT-BUG-1522918?
The affected product for REDHAT-BUG-1522918 is the ISC DHCP Server.
What attack vector is associated with REDHAT-BUG-1522918?
The attack vector associated with REDHAT-BUG-1522918 involves sending empty messages by a malicious client to consume all available socket descriptors.
What type of vulnerability is REDHAT-BUG-1522918?
REDHAT-BUG-1522918 is a Denial of Service vulnerability.