vulnerability

Oracle Linux: CVE-2017-3144: ELSA-2018-0158: dhcp security update (MODERATE)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Dec 7, 2017
Added
Jan 27, 2018
Modified
Dec 3, 2025

Description

A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected but are well beyond their end-of-life (EOL). Releases prior to 4.1.0 have not been tested.
It was found that the DHCP daemon did not properly clean up closed OMAPI connections in certain cases. A remote attacker able to connect to the OMAPI port could use this flaw to exhaust file descriptors in the DHCP daemon, leading to a denial of service in the OMAPI functionality.

Solutions

oracle-linux-upgrade-dhclientoracle-linux-upgrade-dhcporacle-linux-upgrade-dhcp-commonoracle-linux-upgrade-dhcp-develoracle-linux-upgrade-dhcp-libs
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.