Search/CVE-2022-2928
CVE — Medium

CVE-2022-2928

In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increases the option's refcount field. However, there is not a corresponding call to option_dereference() to decrement the refcount field. The function add_option() is only used in server responses to lease query packets. Each lease query response calls this function for several options, so eventually, the reference counters could overflow and cause the server to abort.

CVSS v3.1
6.5 MEDIUM
EPSS
0.69%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Sep 13, 2026
0.00pp
0.68% → 0.69% over 2 tracked changes
CVSS v3.1 Detail
Attack VectorADJACENT
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
ConfidentialityNONE
IntegrityNONE
AvailabilityHIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Connections
4 relationships
Timeline
disclosure → media coverage
Oct 7, 2022
Disclosure — published as a CVE record. · last revised by NVD Nov 21, 2024