REDHAT-BUG-339561: Low severity isc dhcp vulnerability
ISC dhcpd is prone to denial of service attack (daemon crash) when DHCP client specifies large value for dhcp-max-message-size in the request.
Problem only occurs when dhcpd is configured to provide clients with very large amount of DHCP options. Such configurations seems very unlikely to exist in the real deployments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-339561?
The severity of REDHAT-BUG-339561 is classified as a denial of service vulnerability.
How do I fix REDHAT-BUG-339561?
To fix REDHAT-BUG-339561, ensure that dhcpd is not configured to provide excessively large amounts of DHCP options.
What software is affected by REDHAT-BUG-339561?
The software affected by REDHAT-BUG-339561 is ISC DHCP server, commonly referred to as isc-dhcp-server.
What causes the vulnerability REDHAT-BUG-339561?
The vulnerability REDHAT-BUG-339561 is caused when a DHCP client requests a large dhcp-max-message-size, which leads to a daemon crash.
Is REDHAT-BUG-339561 related to any specific configuration?
Yes, REDHAT-BUG-339561 occurs specifically when dhcpd is configured improperly with a very large amount of DHCP options.