Release Info

Advisory: CLSA-2023:1685631644

OS: CentOS 8.5 ELS

Public date: 2023-06-01 11:00:46

Project: dhcp

Version: 4.3.6-45.el8.tuxcare.els1

Errata link: https://errata.cloudlinux.com/centos8.5-els/CLSA-2023-1685631644.html

Changelog

- CVE-2022-2928: option refcount overflow when leasequery is enabled leading to dhcpd abort - CVE-2022-2929: DHCP memory leak - Backported tests from upstream, for this and other CVE`s

Update

Update command: dnf update dhcp*

Packages list

dhcp-client-4.3.6-45.el8.tuxcare.els1.x86_64.rpm dhcp-common-4.3.6-45.el8.tuxcare.els1.noarch.rpm dhcp-devel-4.3.6-45.el8.tuxcare.els1.i686.rpm dhcp-devel-4.3.6-45.el8.tuxcare.els1.x86_64.rpm dhcp-devel-doc-4.3.6-45.el8.tuxcare.els1.noarch.rpm dhcp-libs-4.3.6-45.el8.tuxcare.els1.i686.rpm dhcp-libs-4.3.6-45.el8.tuxcare.els1.x86_64.rpm dhcp-relay-4.3.6-45.el8.tuxcare.els1.x86_64.rpm dhcp-server-4.3.6-45.el8.tuxcare.els1.x86_64.rpm

CVEs

CVE-2022-2928
CVE-2022-2929