PT-2021-3602 · Isc+8 · Isc Dhcp+8

Jon Franklin

+1

·

Published

2021-05-26

·

Updated

2024-06-15

·

CVE-2021-25217

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ISC DHCP versions 4.1-ESV-R1 through 4.1-ESV-R16 ISC DHCP versions 4.4.0 through 4.4.2
Description The issue is related to a buffer overflow in the memory when reading a lease, which can cause a denial of service. The outcome of encountering the defect varies according to the component being affected, whether the package was built as a 32-bit or 64-bit binary, and whether the compiler flag -fstack-protection-strong was used when compiling. In dhclient, it is possible to cause a crash on a 32-bit system when reading an improper lease, leading to network connectivity problems. In dhcpd, when run in DHCPv4 or DHCPv6 mode, the server may exit or improperly delete leases.
Recommendations For ISC DHCP versions 4.1-ESV-R1 through 4.1-ESV-R16, consider updating to a newer version to mitigate the risk. For ISC DHCP versions 4.4.0 through 4.4.2, consider updating to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the lease database to minimize the risk of exploitation. Avoid using the dhcpd server binary built for a 32-bit architecture with the -fstack-protection-strong compiler flag until a patch is available.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1900
ALT-PU-2021-2868
ALT-PU-2021-3334
AZL-6372
BDU:2021-03707
CESA-2021_2357
CESA-2021_2359
CVE-2021-25217
DLA-2674-1
ELSA-2021-2357
ELSA-2021-2359
ELSA-2021-9314
MGASA-2021-0307
OESA-2021-1226
OPENSUSE-SU-2021:0834-1
OPENSUSE-SU-2021:1841-1
OPENSUSE-SU-2021_0834-1
OPENSUSE-SU-2021_1841-1
OPENSUSE-SU-2024:10715-1
RHSA-2021:2357
RHSA-2021:2359
RHSA-2021:2405
RHSA-2021:2414
RHSA-2021:2415
RHSA-2021:2416
RHSA-2021:2418
RHSA-2021:2419
RHSA-2021:2420
RHSA-2021:2469
RHSA-2021:2519
RHSA-2021:2555
RHSA-2021_2357
RHSA-2021_2359
RHSA-2021_2419
RLSA-2021:2359
RLSA-2021_2359
SUSE-SU-2021:14740-1
SUSE-SU-2021:1822-1
SUSE-SU-2021:1841-1
SUSE-SU-2021_14740-1
SUSE-SU-2021_1822-1
SUSE-SU-2021_1841-1
USN-4969-1
USN-4969-2

Affected Products

Alt Linux
Astra Linux
Centos
Isc Dhcp
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu