The DHCPv6 server in ISC DHCP 4.0.x and 4.1.x before 4.1.2-P1, 4.0-ESV and 4.1-ESV before 4.1-ESV-R1, and 4.2.x before 4.2.1b1 allows remote attackers to cause a denial of service (assertion failure and daemon crash) by sending a message over IPv6 for a declined and abandoned address.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade isc-dhcp | Jul 30, 2024 | Jan 31, 2011 |
| Freebsd | — | Upgrade isc-dhcp41-server | Dec 10, 2025 | Jan 28, 2011 |
| Oracle_linux | — | Upgrade dhcp-develUpgrade dhclientUpgrade dhcp | Oct 16, 2024 | Jan 31, 2011 |
| Suse | — | Upgrade dhcp-keamaUpgrade dhcp-develUpgrade dhcpUpgrade dhcp-serverUpgrade dhcp-relayUpgrade dhcp-client | Feb 17, 2015 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub