Alerts This Week
Warning Icon 1 1,003
Alerts This Week
Warning Icon 1 1,003

Ubuntu 14.04 ESM USN-5658-3 Moderate: isc-dhcp Denial Of Service

ubuntu
Calendar Grey November 21, 2022
Dist Ubuntu Esm H88
The Ubuntu Security Notice USN-5658-4 concerns vulnerabilities in isc-dhcp, highlighting potential denial of service risks found in both client and server components.
Several security issues were fixed in DHCP.

Summary

Several security issues were fixed in DHCP.

Software Description:

- isc-dhcp: DHCP server and client

Details:

USN-5658-1 fixed several vulnerabilities in DHCP. This update provides

the corresponding update for Ubuntu 14.04 ESM.

Original advisory details:

It was discovered that DHCP incorrectly handled option reference counting.

A remote attacker could possibly use this issue to cause DHCP servers to

crash, resulting in a denial of service. (CVE-2022-2928)

It was discovered that DHCP incorrectly handled certain memory operations.

A remote attacker could possibly use this issue to cause DHCP clients and

servers to consume resources, leading to a denial of service.

(CVE-2022-2929)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
  isc-dhcp-client                 4.2.4-7ubuntu12.13+esm2
  isc-dhcp-server                 4.2.4-7ubuntu12.13+esm2

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5658-3

https://ubuntu.com/security/notices/USN-5658-1

CVE-2022-2928, CVE-2022-2929

November 21, 2022

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here