dhcpd: use-after-free error leads crash in IPv6 mode when using mismatched BIND libraries
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC contain copies of this, and other, BIND libraries in combinations that have been tested prior to release and are known to not present issues like this. Some third-party packagers of ISC software have modified the dhcpd source, BIND source, or version matchup in ways that create the crash potential. Based on reports available to ISC, the crash probability is large and no analysis has been done on how, or even if, the probability can be manipulated by an attacker. Affects: Builds of dhcpd versions prior to version 4.4.1 when using BIND versions 9.11.2 or later, or BIND versions with specific bug fixes backported to them. ISC does not have access to comprehensive version lists for all repackagings of dhcpd that are vulnerable. In particular, builds from other vendors may also be affected. Operators are advised to consult their vendor documentation.
- Published
- Nov 1, 2019
- Updated
- Jun 16, 2026
- EPSS
- 8.8% · 95th percentile
- CWE
- —
Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.
Report tools
Action score
33
Monitor
Low priority for now.
- CVSS
- 30 / 40 · 7.5 / 10
- CISA KEV
- 0 / 30 · Not listed
- EPSS
- 3 / 30 · 8.8%
CNA vs NVD score
- NVD
- 7.5
- CNA · isc
- 6.5
- 1.0 point gap
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The score given by the assigning authority versus NVD’s independent score. A gap means the severity is contested.
Noroxi analysis
No Noroxi analysis for this record yet
We don't hand-write analysis for the hundreds of thousands of vulnerabilities in the database; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.
We use this product, ask for helpAffected systems
| Vendor | Product | CPE |
|---|---|---|
| isc | dhcpd | cpe:2.3:a:isc:dhcpd |
| redhat | enterprise linux | cpe:2.3:o:redhat:enterprise_linux |
| redhat | enterprise linux desktop | cpe:2.3:o:redhat:enterprise_linux_desktop |
| redhat | enterprise linux eus | cpe:2.3:o:redhat:enterprise_linux_eus |
| redhat | enterprise linux for arm 64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64 |
| redhat | enterprise linux for arm 64 eus | cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus |
| redhat | enterprise linux for ibm z systems | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems |
| redhat | enterprise linux for ibm z systems eus | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus |
| redhat | enterprise linux for power big endian | cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian |
| redhat | enterprise linux for power little endian | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian |
| redhat | enterprise linux for power little endian eus | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus |
| redhat | enterprise linux for scientific computing | cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing |
and 7 more
Affected versions
NVD version ranges (for catalog products). Add the product to your stack with a version and matching uses these.
- isc dhcpdbefore 4.4.1
- opensuse leap15.0
- opensuse leap15.1
- redhat enterprise linux8.0
- redhat enterprise linux desktop7.0
- redhat enterprise linux eus8.1
- redhat enterprise linux eus8.2
- redhat enterprise linux eus8.4
- redhat enterprise linux eus8.6
- redhat enterprise linux eus8.8
- redhat enterprise linux for arm 648.0
- redhat enterprise linux for arm 64 eus8.1_aarch64
- redhat enterprise linux for arm 64 eus8.2_aarch64
- redhat enterprise linux for arm 64 eus8.4_aarch64
- redhat enterprise linux for arm 64 eus8.6_aarch64
- redhat enterprise linux for arm 64 eus8.8_aarch64
- redhat enterprise linux for ibm z systems7.0
- redhat enterprise linux for ibm z systems8.0
- redhat enterprise linux for ibm z systems eus8.1_s390x
- redhat enterprise linux for ibm z systems eus8.2_s390x
Versions reported by the vendor
Affected version ranges reported by the assigning authority (isc). Independent of NVD's CPE analysis and usually ahead of it.
Multiple, non-ISC dhcpd
- builds not wholly from ISC source < 4.4.1affected
Package-level exposure
OSV and GitHub Advisory data: ecosystem, package and range. SBOM matching uses this table.
| Ecosystem | Package | Affected range | Fix |
|---|---|---|---|
| Alpine:v3.11 | dhcp | before 4.4.1-r0 | 4.4.1-r0 |
| Debian:12 | isc-dhcp | before 4.4.1-2 | 4.4.1-2 |
| openSUSE:Leap 15.0 | dhcp | before 4.3.5-lp150.5.3.1 | 4.3.5-lp150.5.3.1 |
| openSUSE:Leap 15.1 | dhcp | before 4.3.5-lp151.6.3.1 | 4.3.5-lp151.6.3.1 |
| openSUSE:Tumbleweed | dhcp | before 4.4.2.P1-2.4 | 4.4.2.P1-2.4 |
| Red Hat:enterprise_linux:7::client | dhclient | before 12:4.2.5-77.el7 | 12:4.2.5-77.el7 |
| Red Hat:enterprise_linux:7::client | dhcp | before 12:4.2.5-77.el7 | 12:4.2.5-77.el7 |
| Red Hat:enterprise_linux:7::client | dhcp-common | before 12:4.2.5-77.el7 | 12:4.2.5-77.el7 |
| Red Hat:enterprise_linux:7::client | dhcp-debuginfo | before 12:4.2.5-77.el7 | 12:4.2.5-77.el7 |
| Red Hat:enterprise_linux:7::client | dhcp-devel | before 12:4.2.5-77.el7 | 12:4.2.5-77.el7 |
| Red Hat:enterprise_linux:7::client | dhcp-libs | before 12:4.2.5-77.el7 | 12:4.2.5-77.el7 |
| Red Hat:enterprise_linux:8::baseos | dhcp | before 12:4.3.6-34.el8 | 12:4.3.6-34.el8 |
| Red Hat:enterprise_linux:8::baseos | dhcp-client | before 12:4.3.6-34.el8 | 12:4.3.6-34.el8 |
| Red Hat:enterprise_linux:8::baseos | dhcp-client-debuginfo | before 12:4.3.6-34.el8 | 12:4.3.6-34.el8 |
| Red Hat:enterprise_linux:8::baseos | dhcp-common | before 12:4.3.6-34.el8 | 12:4.3.6-34.el8 |
| Red Hat:enterprise_linux:8::baseos | dhcp-debuginfo | before 12:4.3.6-34.el8 | 12:4.3.6-34.el8 |
| Red Hat:enterprise_linux:8::baseos | dhcp-debugsource | before 12:4.3.6-34.el8 | 12:4.3.6-34.el8 |
| Red Hat:enterprise_linux:8::baseos | dhcp-libs | before 12:4.3.6-34.el8 | 12:4.3.6-34.el8 |
| Red Hat:enterprise_linux:8::baseos | dhcp-libs-debuginfo | before 12:4.3.6-34.el8 | 12:4.3.6-34.el8 |
| Red Hat:enterprise_linux:8::baseos | dhcp-relay | before 12:4.3.6-34.el8 | 12:4.3.6-34.el8 |
| Red Hat:enterprise_linux:8::baseos | dhcp-relay-debuginfo | before 12:4.3.6-34.el8 | 12:4.3.6-34.el8 |
| Red Hat:enterprise_linux:8::baseos | dhcp-server | before 12:4.3.6-34.el8 | 12:4.3.6-34.el8 |
| Red Hat:enterprise_linux:8::baseos | dhcp-server-debuginfo | before 12:4.3.6-34.el8 | 12:4.3.6-34.el8 |
| SUSE:Linux Enterprise Desktop 12 SP4 | dhcp | before 4.3.3-10.19.1 | 4.3.3-10.19.1 |
+1
Same product
isc: all recordsOther highest-scoring records for the same primary product.
- CVE-2004-0460Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause 54Plan
- CVE-2002-0702Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUP49Plan
- CVE-2004-0461The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses45Plan
- CVE-2004-1006Format string vulnerability in the log functions in dhcpd for dhcp 2.x allows remote DNS servers to execute arbitrary code via certain DNS m42Plan
- CVE-2003-0026Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCP36Monitor
- CVE-2003-0039ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet stor22Monitor
Remediation
Which version to upgrade to
Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.
| Product / package | Fixed version | Source |
|---|---|---|
| alpine:dhcp | 4.4.1-r0 · Alpine:v3.11 | Package registry (OSV) |
| debian:isc-dhcp | 4.4.1-2 · Debian:12 | Package registry (OSV) |
| opensuse:dhcp | 4.3.5-lp150.5.3.1 · openSUSE:Leap 15.0 | Package registry (OSV) |
| red hat:dhclient | 12:4.2.5-77.el7 · Red Hat:enterprise_linux:7::client | Package registry (OSV) |
| red hat:dhcp | 12:4.2.5-77.el7 · Red Hat:enterprise_linux:7::client | Package registry (OSV) |
| red hat:dhcp-client | 12:4.3.6-34.el8 · Red Hat:enterprise_linux:8::baseos | Package registry (OSV) |
| red hat:dhcp-client-debuginfo | 12:4.3.6-34.el8 · Red Hat:enterprise_linux:8::baseos | Package registry (OSV) |
| red hat:dhcp-common | 12:4.2.5-77.el7 · Red Hat:enterprise_linux:7::client | Package registry (OSV) |
| red hat:dhcp-debuginfo | 12:4.2.5-77.el7 · Red Hat:enterprise_linux:7::client | Package registry (OSV) |
| red hat:dhcp-debugsource | 12:4.3.6-34.el8 · Red Hat:enterprise_linux:8::baseos | Package registry (OSV) |
| red hat:dhcp-devel | 12:4.2.5-77.el7 · Red Hat:enterprise_linux:7::client | Package registry (OSV) |
| red hat:dhcp-libs | 12:4.2.5-77.el7 · Red Hat:enterprise_linux:7::client | Package registry (OSV) |
| red hat:dhcp-libs-debuginfo | 12:4.3.6-34.el8 · Red Hat:enterprise_linux:8::baseos | Package registry (OSV) |
| red hat:dhcp-relay | 12:4.3.6-34.el8 · Red Hat:enterprise_linux:8::baseos | Package registry (OSV) |
| red hat:dhcp-relay-debuginfo | 12:4.3.6-34.el8 · Red Hat:enterprise_linux:8::baseos | Package registry (OSV) |
| suse:dhcp | 4.3.5-6.3.1 · SUSE:Linux Enterprise Module for Basesystem 15 | Package registry (OSV) |
Exploit status
No known public exploit
No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.
Research context
For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.
Timeline
From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.
No dated events beyond publication.
FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).
Patch and commit links
Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.
No commit or PR link among the references.
Credits
All researchersFinders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.
No credits in the CNA record.
Variant candidates
Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.
No nightly-computed relations.
Chain candidates
An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.
—
Bug bounty scope
No known public program.
Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).
Technical details
Attack conditions
- Anyone who can reach it over the internet can trigger it.
- No account or password is required.
- No user action is required.
- No special conditions are required; it is repeatable.
If successful
- Confidentiality
- none
- Integrity
- none
- Availability
- high · the service can be disrupted
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality impact
- None
- Integrity impact
- None
- Availability impact
- High
Weakness class (CWE)
—
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd-primary
Attack context
MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.
MITRE has no CAPEC/ATT&CK mapping for this CWE.
Change log
- Fix✗ → ✓
For records you follow, these changes also arrive as notifications. →
References
- access.redhat.com/errata/RHSA-2019:2060
- access.redhat.com/errata/RHSA-2019:3525
- lists.opensuse.org/opensuse-security-announce/2019-10/msg00048.html
- lists.opensuse.org/opensuse-security-announce/2019-10/msg00049.html
Vendor advisories and official records. Exploit/PoC links are deliberately left out.