A buffer overrun in lease file parsing code can be used to exploit a common vulnerability shared by dhcpd and dhclient
Published May 26, 2021
8.8
HIGHCVSS 3.1
EPSS 6.12%
Description
In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the defect is also present in releases from those series, but they have not been officially tested for the vulnerability), The outcome of encountering the defect while reading a lease that will trigger it varies, according to: the component being affected (i.e., dhclient or dhcpd) whether the package was built as a 32-bit or 64-bit binary whether the compiler flag -fstack-protection-strong was used when compiling In dhclient, ISC has not successfully reproduced the error on a 64-bit system. However, on a 32-bit system it is possible to cause dhclient to crash when reading an improper lease, which could cause network connectivity problems for an affected system due to the absence of a running DHCP client process. In dhcpd, when run in DHCPv4 or DHCPv6 mode: if the dhcpd server binary was built for a 32-bit architecture AND the -fstack-protection-strong flag was specified to the compiler, dhcpd may exit while parsing a lease file containing an objectionable lease, resulting in lack of service to clients. Additionally, the offending lease and the lease immediately following it in the lease database may be improperly deleted. if the dhcpd server binary was built for a 64-bit architecture OR if the -fstack-protection-strong compiler flag was NOT specified, the crash will not occur, but it is possible for the offending lease and the lease which immediately followed it to be improperly deleted.
Affected products
-
- Version 4.1 ESVStatusaffectedConstraints<4.1-ESV-R16-P1
- Version 4.4StatusaffectedConstraints<4.4.2-P1
- Version
Configuration 1
- ≥ 4.4.0 · ≤ 4.4.2
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
Configuration 2
- 33
- 34
Configuration 3
- 9.0
Configuration 4
- < 2.15.0
Running on/with
- n/a
Configuration 5
- ≥ 2.3.0 · < 2.15.0
Running on/with
- n/a
Configuration 6
- ≥ 2.3.0 · < 2.15.0
Running on/with
- n/a
Configuration 7
- ≥ 2.3.0 · < 2.15.0
Running on/with
- n/a
Configuration 8
- ≥ 2.3.0 · < 2.15.0
Running on/with
- n/a
Configuration 9
- ≥ 2.3.0 · < 2.15.0
Running on/with
- n/a
Configuration 10
- < 2.15.0
Running on/with
- n/a
Configuration 11
- < 2.15.0
Running on/with
- n/a
Configuration 12
- ≥ 2.3.0 · < 2.15.0
Running on/with
- n/a
Configuration 13
- ≥ 2.3.0 · < 2.15.0
Running on/with
- n/a
Configuration 14
- n/a
- n/a
No data.
Red Hat Enterprise Linux 6 Extended Lifecycle Support
dhcp-12:4.1.1-64.P1.el6_10
Fixed · RHSA-2021:2419
Red Hat Enterprise Linux 7
dhcp-12:4.2.5-83.el7_9.1
Fixed · RHSA-2021:2357
Red Hat Enterprise Linux 7.2 Advanced Update Support
dhcp-12:4.2.5-42.el7_2.2
Fixed · RHSA-2021:2418
Red Hat Enterprise Linux 7.3 Advanced Update Support
dhcp-12:4.2.5-47.el7_3.2
Fixed · RHSA-2021:2415
Red Hat Enterprise Linux 7.4 Advanced Update Support
dhcp-12:4.2.5-58.el7_4.5
Fixed · RHSA-2021:2414
Red Hat Enterprise Linux 7.4 Telco Extended Update Support
dhcp-12:4.2.5-58.el7_4.5
Fixed · RHSA-2021:2414
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
dhcp-12:4.2.5-58.el7_4.5
Fixed · RHSA-2021:2414
Red Hat Enterprise Linux 7.6 Advanced Update Support
dhcp-12:4.2.5-69.el7_6.1
Fixed · RHSA-2021:2469
Red Hat Enterprise Linux 7.6 Telco Extended Update Support
dhcp-12:4.2.5-69.el7_6.1
Fixed · RHSA-2021:2469
Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions
dhcp-12:4.2.5-69.el7_6.1
Fixed · RHSA-2021:2469
Red Hat Enterprise Linux 7.7 Extended Update Support
dhcp-12:4.2.5-77.el7_7.1
Fixed · RHSA-2021:2405
Red Hat Enterprise Linux 8
dhcp-12:4.3.6-44.el8_4.1
Fixed · RHSA-2021:2359
Red Hat Enterprise Linux 8.1 Extended Update Support
dhcp-12:4.3.6-34.el8_1.2
Fixed · RHSA-2021:2416
Red Hat Enterprise Linux 8.2 Extended Update Support
dhcp-12:4.3.6-40.el8_2.2
Fixed · RHSA-2021:2420
Red Hat OpenShift Container Platform 4.7
cri-o-0:1.20.3-6.rhaos4.7.git0d0f863.el7
Fixed · RHSA-2021:2555
Red Hat OpenShift Container Platform 4.7
dhcp-12:4.3.6-41.el8_3.1
Fixed · RHSA-2021:2555
Red Hat OpenShift Container Platform 4.7
openshift-clients-0:4.7.0-202106252127.p0.git.8b4b094.el7
Fixed · RHSA-2021:2555
Red Hat OpenShift Container Platform 4.7
openshift-kuryr-0:4.7.0-202106232224.p0.git.c7654fb.el8
Fixed · RHSA-2021:2555
Red Hat OpenShift Container Platform 4.7
polkit-0:0.115-11.el8_3.2
Fixed · RHSA-2021:2555
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.3.16-20210615.0.el7_9
Fixed · RHSA-2021:2519
Red Hat Enterprise Linux 9
dhcp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Extended Lifecycle Support | dhcp-12:4.1.1-64.P1.el6_10 | Fixed | RHSA-2021:2419 |
| Red Hat Enterprise Linux 7 | dhcp-12:4.2.5-83.el7_9.1 | Fixed | RHSA-2021:2357 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | dhcp-12:4.2.5-42.el7_2.2 | Fixed | RHSA-2021:2418 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | dhcp-12:4.2.5-47.el7_3.2 | Fixed | RHSA-2021:2415 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | dhcp-12:4.2.5-58.el7_4.5 | Fixed | RHSA-2021:2414 |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | dhcp-12:4.2.5-58.el7_4.5 | Fixed | RHSA-2021:2414 |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | dhcp-12:4.2.5-58.el7_4.5 | Fixed | RHSA-2021:2414 |
| Red Hat Enterprise Linux 7.6 Advanced Update Support | dhcp-12:4.2.5-69.el7_6.1 | Fixed | RHSA-2021:2469 |
| Red Hat Enterprise Linux 7.6 Telco Extended Update Support | dhcp-12:4.2.5-69.el7_6.1 | Fixed | RHSA-2021:2469 |
| Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions | dhcp-12:4.2.5-69.el7_6.1 | Fixed | RHSA-2021:2469 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | dhcp-12:4.2.5-77.el7_7.1 | Fixed | RHSA-2021:2405 |
| Red Hat Enterprise Linux 8 | dhcp-12:4.3.6-44.el8_4.1 | Fixed | RHSA-2021:2359 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | dhcp-12:4.3.6-34.el8_1.2 | Fixed | RHSA-2021:2416 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | dhcp-12:4.3.6-40.el8_2.2 | Fixed | RHSA-2021:2420 |
| Red Hat OpenShift Container Platform 4.7 | cri-o-0:1.20.3-6.rhaos4.7.git0d0f863.el7 | Fixed | RHSA-2021:2555 |
| Red Hat OpenShift Container Platform 4.7 | dhcp-12:4.3.6-41.el8_3.1 | Fixed | RHSA-2021:2555 |
| Red Hat OpenShift Container Platform 4.7 | openshift-clients-0:4.7.0-202106252127.p0.git.8b4b094.el7 | Fixed | RHSA-2021:2555 |
| Red Hat OpenShift Container Platform 4.7 | openshift-kuryr-0:4.7.0-202106232224.p0.git.c7654fb.el8 | Fixed | RHSA-2021:2555 |
| Red Hat OpenShift Container Platform 4.7 | polkit-0:0.115-11.el8_3.2 | Fixed | RHSA-2021:2555 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.3.16-20210615.0.el7_9 | Fixed | RHSA-2021:2519 |
| Red Hat Enterprise Linux 9 | dhcp | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of ISC DHCP:
ISC DHCP 4.1-ESV-R16-P1 ISC DHCP 4.4.2-P1
Red Hat statement
To abuse this flaw an attacker has to be on the same local sub-net of the victim machine. An attacker may send crafted DHCP messages with long lease statements that, when stored locally on file and then re-read by dhclient or dhcpd, might trigger the bug.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:A/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (25 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.12% (0.06118) | 93.22th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.12% (0.06118) | 92.49th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.55% (0.00550) | 67.09th | v4 (v2025.03.14) |
| Nov 18, 2025 | 3.58% (0.03579) | 86.56th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.22% (0.00220) | 42.59th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.28% (0.00277) | 69.07th | v3 (v2023.03.01) |
| Feb 9, 2024 | 0.28% (0.00277) | 67.30th | v3 (v2023.03.01) |
| Dec 31, 2023 | 0.19% (0.00195) | 57.38th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.14% (0.00137) | 48.93th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.14% (0.00145) | 48.65th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.60% (0.02596) | 82.09th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.77% (0.01769) | 74.48th | v2 (v2022.01.01) |
| Mar 25, 2022 | 5.21% (0.05206) | 75.75th | v2 (v2022.01.01) |
| Mar 24, 2022 | 3.41% (0.03410) | 66.90th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.84% (0.02841) | 63.98th | v2 (v2022.01.01) |
| Feb 3, 2022 | 5.36% (0.05363) | 79.74th | v1 |
| Jan 6, 2022 | 5.36% (0.05363) | 79.54th | v1 |
| Jan 5, 2022 | 1.25% (0.01247) | 69.74th | v1 |
| Jun 11, 2021 | 1.25% (0.01247) | 0.00th | v1 |
| Jun 10, 2021 | 5.36% (0.05363) | 0.00th | v5 (v2026.06.15) |
| Jun 6, 2021 | 5.36% (0.05363) | 0.00th | v1 |
| Jun 5, 2021 | 1.25% (0.01247) | 0.00th | v1 |
| Jun 4, 2021 | 1.04% (0.01040) | 0.00th | v1 |
| Jun 3, 2021 | 0.83% (0.00833) | 0.00th | v1 |
| May 27, 2021 | 0.62% (0.00624) | 0.00th | v1 |
References (13)
- http://www.openwall.com/lists/oss-security/2021/05/26/6 mailing-listMailing ListPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2021-25217 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1963258 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-406691.pdf PatchThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf PatchThird Party Advisory
- https://kb.isc.org/docs/cve-2021-25217 ExploitVendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/06/msg00002.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5QI4DYC7J4BGHEW3NH4XHMWTHYC36UK4/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z2LB42JWIV4M4WDNXX5VGIP26FEYWKIF/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-25217
- https://security.gentoo.org/glsa/202305-22 vendor-advisory
- https://security.netapp.com/advisory/ntap-20220325-0011/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-25217
Change history (0)
No recorded changes yet.