Source: isc-dhcp Version: 4.4.3-2 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org> Control: found -1 4.4.1-2.3 Control: fixed -1 4.4.1-2.3+deb11u1
Hi, The following vulnerabilities were published for isc-dhcp. CVE-2022-2928[0]: | An option refcount overflow exists in dhcpd CVE-2022-2929[1]: | DHCP memory leak 4.4.1-2.3+deb11u1 is uploaded to security-master and pending a DSA release. If needed I can try to contribute a NMU for unstable/bookworm. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2022-2928 https://www.cve.org/CVERecord?id=CVE-2022-2928 https://kb.isc.org/docs/cve-2022-2928 [1] https://security-tracker.debian.org/tracker/CVE-2022-2929 https://www.cve.org/CVERecord?id=CVE-2022-2929 https://kb.isc.org/docs/cve-2022-2929 [2] https://lists.isc.org/pipermail/dhcp-announce/2022-October/000437.html Regards, Salvatore