Back

HIGH

A malicious client can overflow a reference counter in ISC dhcpd

Published Jan 16, 2019

Description

A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of DHCP.

DHCP 4.1-ESV-R15-P1 DHCP 4.3.6-P1 DHCP 4.4.1

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Jan 16, 2019
Updated Apr 25, 2025
Reserved Jan 17, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 28, 2018