An option refcount overflow exists in dhcpd
Published Oct 7, 2022
6.5
MEDIUMCVSS 3.1
EPSS 0.69%
Description
In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increases the option's refcount field. However, there is not a corresponding call to option_dereference() to decrement the refcount field. The function add_option() is only used in server responses to lease query packets. Each lease query response calls this function for several options, so eventually, the reference counters could overflow and cause the server to abort.
Affected products
-
- Version 4.1 ESV 4.1-ESV-R1 through versions before 4.1-ESV-R16-P1StatusaffectedConstraints-
- Version 4.4.0 through versions before 4.4.3-P1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
- ≥ 4.4.0 · ≤ 4.4.3
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
- 4.1-esv
Configuration 2
- 10.0
Configuration 3
- 35
- 36
- 37
No data.
Red Hat Enterprise Linux 8
dhcp-12:4.3.6-49.el8
Fixed · RHSA-2023:3000
Red Hat Enterprise Linux 9
dhcp-12:4.4.2-18.b1.el9
Fixed · RHSA-2023:2502
Red Hat Enterprise Linux 6
dhcp
Out of support scope
Red Hat Enterprise Linux 7
dhcp
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | dhcp-12:4.3.6-49.el8 | Fixed | RHSA-2023:3000 |
| Red Hat Enterprise Linux 9 | dhcp-12:4.4.2-18.b1.el9 | Fixed | RHSA-2023:2502 |
| Red Hat Enterprise Linux 6 | dhcp | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | dhcp | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of ISC DHCP. These can all be downloaded from https://www.isc.org/downloads. 4.4.3-P1 4.1-ESV-R16-P2
Red Hat statement
Vulnerable servers are network accessible to an attacker and configured to allow and process lease queries. Internally, reference counters are integers and thus overflow at 2^31 references, so even at 1000 lease query responses per second, it would take more than three weeks to crash the server.
Red Hat mitigation
Possible workaround - Disable lease query on the server for DHCPv4 or restart the server periodically.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.69% (0.00686) | 50.88th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.67% (0.00670) | 46.95th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.04% (0.00041) | 9.45th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.11% (0.00107) | 45.05th | v3 (v2023.03.01) |
| May 14, 2024 | 0.11% (0.00107) | 43.03th | v3 (v2023.03.01) |
| Apr 29, 2024 | 0.09% (0.00092) | 38.59th | v3 (v2023.03.01) |
| Jan 12, 2024 | 0.08% (0.00085) | 35.51th | v3 (v2023.03.01) |
| Nov 9, 2023 | 0.06% (0.00060) | 23.97th | v3 (v2023.03.01) |
| May 4, 2023 | 0.05% (0.00050) | 17.37th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.63% (0.01626) | 75.89th | v2 (v2022.01.01) |
| Oct 18, 2022 | 1.63% (0.01626) | 75.16th | v2 (v2022.01.01) |
| Oct 15, 2022 | 0.95% (0.00954) | 34.95th | v2 (v2022.01.01) |
| Oct 7, 2022 | 0.89% (0.00885) | 26.49th | v2 (v2022.01.01) |
References (10)
- https://access.redhat.com/security/cve/CVE-2022-2928 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2132002 Issue Tracking
- https://kb.isc.org/docs/cve-2022-2928 Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00015.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2SARIK7KZ7MGQIWDRWZFAOSQSPXY4GOU/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QQXYCIWUDILRCNBAIMVFCSGXBRKEPB4K/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6IBFH4MRRNJQVWEKILQ6I6CXWW766FX/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2928
- https://security.gentoo.org/glsa/202305-22 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2022-2928
Change history (0)
No recorded changes yet.