PT-2019-10991 · Isc · Kea Dhcp
Published
2019-01-16
·
Updated
2019-10-09
·
CVE-2018-5739
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Kea DHCP version 1.4.0
Description:
A memory leak issue affects operators using certain hooks library facilities, specifically those that utilize
query4 or query6 parameters in their callouts. This leak results from the improper freeing of memory in the callout handle store, introduced to support multiple requests simultaneously. The issue leads to the exhaustion of available memory and the subsequent failure of the server process.Recommendations:
For Kea DHCP version 1.4.0, consider disabling hooks that use
query4 or query6 parameters in their callouts as a temporary workaround to prevent memory leaks. Restrict access to these hooks to minimize the risk of exploitation until a proper fix is available.Fix
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kea Dhcp