{"id":"MGASA-2022-0374","summary":"Updated dhcp packages fix security vulnerability","details":"In ISC DHCP 4.4.0 -\u003e 4.4.3, ISC DHCP 4.1-ESV-R1 -\u003e 4.1-ESV-R16-P1, when\nthe function option_code_hash_lookup() is called from add_option(), it\nincreases the option's refcount field. However, there is not a\ncorresponding call to option_dereference() to decrement the refcount\nfield. The function add_option() is only used in server responses to\nlease query packets. Each lease query response calls this function for\nseveral options, so eventually, the reference counters could overflow and\ncause the server to abort. (CVE-2022-2928)\n\nIn ISC DHCP 1.0 -\u003e 4.4.3, ISC DHCP 4.1-ESV-R1 -\u003e 4.1-ESV-R16-P1 a system\nwith access to a DHCP server, sending DHCP packets crafted to include fqdn\nlabels longer than 63 bytes, could eventually cause the server to run out\nof memory. (CVE-2022-2929)\n","modified":"2026-04-16T00:12:35.452309797Z","published":"2022-10-18T23:14:56Z","upstream":["CVE-2022-2928","CVE-2022-2929"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2022-0374.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=30942"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2022-2928"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2022-2929"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2022/10/05/1"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5658-1"}],"affected":[{"package":{"name":"dhcp","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/dhcp?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4.2-10.2.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2022-0374.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}