CVE-2021-25217

In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the defect is also present in releases from those series, but they have not been officially tested for the vulnerability), The outcome of encountering the defect while reading a lease that will trigger it varies, according to: the component being affected (i.e., dhclient or dhcpd) whether the package was built as a 32-bit or 64-bit binary whether the compiler flag -fstack-protection-strong was used when compiling In dhclient, ISC has not successfully reproduced the error on a 64-bit system. However, on a 32-bit system it is possible to cause dhclient to crash when reading an improper lease, which could cause network connectivity problems for an affected system due to the absence of a running DHCP client process. In dhcpd, when run in DHCPv4 or DHCPv6 mode: if the dhcpd server binary was built for a 32-bit architecture AND the -fstack-protection-strong flag was specified to the compiler, dhcpd may exit while parsing a lease file containing an objectionable lease, resulting in lack of service to clients. Additionally, the offending lease and the lease immediately following it in the lease database may be improperly deleted. if the dhcpd server binary was built for a 64-bit architecture OR if the -fstack-protection-strong compiler flag was NOT specified, the crash will not occur, but it is possible for the offending lease and the lease which immediately followed it to be improperly deleted.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
Affected Products (NVD)
VendorProductVersion
iscdhcp
4.4.0 ≤
𝑥
≤ 4.4.2
iscdhcp
4.1-esv:r1
iscdhcp
4.1-esv:r10
iscdhcp
4.1-esv:r10_b1
iscdhcp
4.1-esv:r10_rc1
iscdhcp
4.1-esv:r10b1
iscdhcp
4.1-esv:r10rc1
iscdhcp
4.1-esv:r11
iscdhcp
4.1-esv:r11_b1
iscdhcp
4.1-esv:r11_rc1
iscdhcp
4.1-esv:r11_rc2
iscdhcp
4.1-esv:r11b1
iscdhcp
4.1-esv:r11rc1
iscdhcp
4.1-esv:r11rc2
iscdhcp
4.1-esv:r12
iscdhcp
4.1-esv:r12-p1
iscdhcp
4.1-esv:r12_b1
iscdhcp
4.1-esv:r12_p1
iscdhcp
4.1-esv:r12b1
iscdhcp
4.1-esv:r13
iscdhcp
4.1-esv:r13_b1
iscdhcp
4.1-esv:r13b1
iscdhcp
4.1-esv:r14
iscdhcp
4.1-esv:r14_b1
iscdhcp
4.1-esv:r14b1
iscdhcp
4.1-esv:r15
iscdhcp
4.1-esv:r15-p1
iscdhcp
4.1-esv:r15_b1
iscdhcp
4.1-esv:r16
debiandebian_linux
9.0
siemensruggedcom_rox_rx1400_firmware
𝑥
< 2.15.0
siemensruggedcom_rox_rx1500_firmware
2.3.0 ≤
𝑥
< 2.15.0
siemensruggedcom_rox_rx1501_firmware
2.3.0 ≤
𝑥
< 2.15.0
siemensruggedcom_rox_rx1510_firmware
2.3.0 ≤
𝑥
< 2.15.0
siemensruggedcom_rox_rx1511_firmware
2.3.0 ≤
𝑥
< 2.15.0
siemensruggedcom_rox_rx1512_firmware
2.3.0 ≤
𝑥
< 2.15.0
siemensruggedcom_rox_rx1524_firmware
𝑥
< 2.15.0
siemensruggedcom_rox_rx1536_firmware
𝑥
< 2.15.0
siemensruggedcom_rox_rx5000_firmware
2.3.0 ≤
𝑥
< 2.15.0
siemensruggedcom_rox_mx5000_firmware
2.3.0 ≤
𝑥
< 2.15.0
netappontap_select_deploy_administration_utility
-
netappsolidfire_\&_hci_management_node
-
siemenssinec_ins
𝑥
< 1.0
siemenssinec_ins
1.0
siemenssinec_ins
1.0:sp1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
isc-dhcp
bookworm
4.4.3-P1-2
fixed
bullseye
4.4.1-2.3+deb11u2
fixed
bullseye (security)
4.4.1-2.3+deb11u1
fixed
sid
4.4.3-P1-5
fixed
trixie
4.4.3-P1-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
isc-dhcp
bionic
Fixed 4.3.5-3ubuntu7.3
released
focal
Fixed 4.4.1-2.1ubuntu5.20.04.2
released
groovy
Fixed 4.4.1-2.1ubuntu10.1
released
hirsute
Fixed 4.4.1-2.2ubuntu6.1
released
impish
Fixed 4.4.1-2.2ubuntu7
released
jammy
Fixed 4.4.1-2.2ubuntu7
released
trusty
Fixed 4.2.4-7ubuntu12.13+esm1
released
xenial
Fixed 4.3.3-5ubuntu12.10+esm1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
dhcp
suse enterprise sap 12 SP3
4.3.3-10.22.1
fixed
suse enterprise sap 12 SP4
4.3.3-10.22.1
fixed
suse enterprise sap 12 SP5
4.3.3-10.22.1
fixed
suse enterprise server 12 SP2
4.3.3-10.22.1
fixed
suse enterprise server 12 SP3
4.3.3-10.22.1
fixed
suse enterprise server 12 SP4
4.3.3-10.22.1
fixed
suse enterprise server 12 SP5
4.3.3-10.22.1
fixed
dhcp-client
suse enterprise sap 12 SP3
4.3.3-10.22.1
fixed
suse enterprise sap 12 SP4
4.3.3-10.22.1
fixed
suse enterprise sap 12 SP5
4.3.3-10.22.1
fixed
suse enterprise server 12 SP2
4.3.3-10.22.1
fixed
suse enterprise server 12 SP3
4.3.3-10.22.1
fixed
suse enterprise server 12 SP4
4.3.3-10.22.1
fixed
suse enterprise server 12 SP5
4.3.3-10.22.1
fixed
dhcp-relay
suse enterprise sap 12 SP3
4.3.3-10.22.1
fixed
suse enterprise sap 12 SP4
4.3.3-10.22.1
fixed
suse enterprise sap 12 SP5
4.3.3-10.22.1
fixed
suse enterprise server 12 SP2
4.3.3-10.22.1
fixed
suse enterprise server 12 SP3
4.3.3-10.22.1
fixed
suse enterprise server 12 SP4
4.3.3-10.22.1
fixed
suse enterprise server 12 SP5
4.3.3-10.22.1
fixed
dhcp-server
suse enterprise sap 12 SP3
4.3.3-10.22.1
fixed
suse enterprise sap 12 SP4
4.3.3-10.22.1
fixed
suse enterprise sap 12 SP5
4.3.3-10.22.1
fixed
suse enterprise server 12 SP2
4.3.3-10.22.1
fixed
suse enterprise server 12 SP3
4.3.3-10.22.1
fixed
suse enterprise server 12 SP4
4.3.3-10.22.1
fixed
suse enterprise server 12 SP5
4.3.3-10.22.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
dhclient
RHEL 7
12:4.2.5-83.el7_9.1
fixed
dhcp
RHEL 7
12:4.2.5-83.el7_9.1
fixed
dhcp-client
RHEL 8
12:4.3.6-44.el8_4.1
fixed
RHEL 8.1 E4S
12:4.3.6-34.el8_1.2
fixed
RHEL 8.1 EUS
12:4.3.6-34.el8_1.2
fixed
RHEL 8.2 AUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 E4S
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 EUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 TUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.4 AUS
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 E4S
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 EUS
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 TUS
12:4.3.6-44.el8_4.1
fixed
dhcp-common
RHEL 7
12:4.2.5-83.el7_9.1
fixed
RHEL 8
12:4.3.6-44.el8_4.1
fixed
RHEL 8.1 E4S
12:4.3.6-34.el8_1.2
fixed
RHEL 8.1 EUS
12:4.3.6-34.el8_1.2
fixed
RHEL 8.2 AUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 E4S
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 EUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 TUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.4 AUS
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 E4S
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 EUS
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 TUS
12:4.3.6-44.el8_4.1
fixed
dhcp-devel
RHEL 7
12:4.2.5-83.el7_9.1
fixed
dhcp-libs
RHEL 7
12:4.2.5-83.el7_9.1
fixed
RHEL 8
12:4.3.6-44.el8_4.1
fixed
RHEL 8.1 E4S
12:4.3.6-34.el8_1.2
fixed
RHEL 8.1 EUS
12:4.3.6-34.el8_1.2
fixed
RHEL 8.2 AUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 E4S
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 EUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 TUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.4 AUS
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 E4S
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 EUS
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 TUS
12:4.3.6-44.el8_4.1
fixed
dhcp-relay
RHEL 8
12:4.3.6-44.el8_4.1
fixed
RHEL 8.1 E4S
12:4.3.6-34.el8_1.2
fixed
RHEL 8.1 EUS
12:4.3.6-34.el8_1.2
fixed
RHEL 8.2 AUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 E4S
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 EUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 TUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.4 AUS
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 E4S
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 EUS
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 TUS
12:4.3.6-44.el8_4.1
fixed
dhcp-server
RHEL 8
12:4.3.6-44.el8_4.1
fixed
RHEL 8.1 E4S
12:4.3.6-34.el8_1.2
fixed
RHEL 8.1 EUS
12:4.3.6-34.el8_1.2
fixed
RHEL 8.2 AUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 E4S
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 EUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.2 TUS
12:4.3.6-40.el8_2.2
fixed
RHEL 8.4 AUS
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 E4S
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 EUS
12:4.3.6-44.el8_4.1
fixed
RHEL 8.4 TUS
12:4.3.6-44.el8_4.1
fixed