Source: isc-dhcp
Version: 4.4.3-2
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>
Control: found -1 4.4.1-2.3
Control: fixed -1 4.4.1-2.3+deb11u1

Hi,

The following vulnerabilities were published for isc-dhcp.

CVE-2022-2928[0]:
| An option refcount overflow exists in dhcpd

CVE-2022-2929[1]:
| DHCP memory leak

4.4.1-2.3+deb11u1 is uploaded to security-master and pending a DSA
release.

If needed I can try to contribute a NMU for unstable/bookworm.

If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2022-2928
    https://www.cve.org/CVERecord?id=CVE-2022-2928
    https://kb.isc.org/docs/cve-2022-2928
[1] https://security-tracker.debian.org/tracker/CVE-2022-2929
    https://www.cve.org/CVERecord?id=CVE-2022-2929
    https://kb.isc.org/docs/cve-2022-2929
[2] https://lists.isc.org/pipermail/dhcp-announce/2022-October/000437.html

Regards,
Salvatore

Reply via email to