Input validation error in DHCP - CVE-2021-25217
Published: May 27, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack or gain access to sensitive information.
The vulnerability exists due to insufficient validation of options data stored in DHCP leases. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack or gain access to sensitive information.
Both dhcpd and dhclient are affected by the vulnerability.
Affected software
Gentoo Linux
Amazon Linux AMI
Arch Linux
SUSE Manager Server
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
CentOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
IBM i
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
HPE Helion Openstack
SUSE OpenStack Cloud
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud Crowbar
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Server Applications
openEuler
Fedora
RUGGEDCOM ROX RX5000
RUGGEDCOM ROX RX1512
RUGGEDCOM ROX RX1511
RUGGEDCOM ROX RX1510
RUGGEDCOM ROX RX1501
RUGGEDCOM ROX RX1500
RUGGEDCOM ROX MX5000
RUGGEDCOM ROX RX1400
RUGGEDCOM ROX RX1524
RUGGEDCOM ROX RX1536
cflinuxfs3
Dell EMC PowerProtect Data Protection
IBM Cloud Foundry Migration Runtime
IBM System Storage TS4500 Tape Library
SmartFabric OS10
cri-o (Red Hat package)
dhcp (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
openshift-kuryr (Red Hat package)
openshift-clients (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
dhcp-client
dhcp-relay
dhcp
dhcp-server
dhcp-debuginfo
dhcp-debugsource
dhcp-client-debuginfo
dhcp-relay-debuginfo
dhcp-server-debuginfo
dhcp-devel
isc-dhcp-client (Ubuntu package)
isc-dhcp-server (Ubuntu package)
dhcp-common
dhcp-libs
dhcp-help
Red Hat Virtualization Host
Red Hat Virtualization
OpenShift Virtualization
Red Hat OpenShift Container Platform
SINEC INS
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
SecurID Authentication Manager
How to mitigate CVE-2021-25217
RUGGEDCOM ROX RX5000 - update to 2.15.0
RUGGEDCOM ROX RX1512 - update to 2.15.0
RUGGEDCOM ROX RX1511 - update to 2.15.0
RUGGEDCOM ROX RX1510 - update to 2.15.0
RUGGEDCOM ROX RX1501 - update to 2.15.0
RUGGEDCOM ROX RX1500 - update to 2.15.0
RUGGEDCOM ROX MX5000 - update to 2.15.0
cflinuxfs3 - update to 0.241.0
cri-o (Red Hat package) - addressed in versions 1.20.3-6.rhaos4.7.git0d0f863.el7, 1.20.3-6.rhaos4.7.git0d0f863.el8
Dell EMC PowerProtect Data Protection - update to 2.7.8
IBM Cloud Foundry Migration Runtime - update to 4.1.2
dhcp (Red Hat package) - addressed in versions 4.1.1-64.P1.el6_10, 4.2.5-42.el7_2.2, 4.2.5-47.el7_3.2, 4.2.5-58.el7_4.5, 4.2.5-69.el7_6.1, 4.2.5-77.el7_7.1, 4.2.5-83.el7_9.1, 4.3.6-34.el8_1.2, 4.3.6-40.el8_2.2, 4.3.6-44.el8_4.1
redhat-release-virtualization-host (Red Hat package) - update to 4.3.16-1.el7ev
redhat-virtualization-host (Red Hat package) - update to 4.3.16-20210615.0.el7_9
Red Hat OpenShift Container Platform - update to 4.7.19
openshift-kuryr (Red Hat package) - update to 4.7.0-202106232224.p0.git.c7654fb.el8
openshift-clients (Red Hat package) - addressed in versions 4.7.0-202106252127.p0.git.8b4b094.el7, 4.7.0-202106252127.p0.git.8b4b094.el8
SINEC INS - update to 1.0 SP2
IBM System Storage TS4500 Tape Library - addressed in versions 1.7.0.5, 1.8.0.1
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
RUGGEDCOM ROX RX1400 - update to 2.15.0
RUGGEDCOM ROX RX1524 - update to 2.15.0
RUGGEDCOM ROX RX1536 - update to 2.15.0
dhcp-client - addressed in versions 4.2.4.P2-0.28.12.1, 4.3.3-10.22.1, 4.3.6.P1-6.11.1
dhcp-relay - addressed in versions 4.2.4.P2-0.28.12.1, 4.3.3-10.22.1, 4.3.6.P1-6.11.1
dhcp - addressed in versions 4.2.4.P2-0.28.12.1, 4.3.3-10.22.1, 4.3.6.P1-6.11.1
dhcp-server - addressed in versions 4.2.4.P2-0.28.12.1, 4.3.3-10.22.1, 4.3.6.P1-6.11.1
dhcp-debuginfo - addressed in versions 4.2.4.P2-0.28.12.1, 4.3.3-10.22.1, 4.3.6.P1-6.11.1
dhcp-debugsource - addressed in versions 4.2.4.P2-0.28.12.1, 4.3.3-10.22.1, 4.3.6.P1-6.11.1
dhcp-client-debuginfo - addressed in versions 4.3.3-10.22.1, 4.3.6.P1-6.11.1
dhcp-relay-debuginfo - addressed in versions 4.3.3-10.22.1, 4.3.6.P1-6.11.1
dhcp-server-debuginfo - addressed in versions 4.3.3-10.22.1, 4.3.6.P1-6.11.1
dhcp-devel - addressed in versions 4.3.3-10.22.1, 4.3.6.P1-6.11.1
isc-dhcp-client (Ubuntu package) - addressed in versions 4.3.5-3ubuntu7.3, 4.3.35ubuntu12.10+esm1, 4.4.1-2.1ubuntu5.20.04.2, 4.4.1-2.1ubuntu10.1, 4.4.1-2.2ubuntu6.1
isc-dhcp-server (Ubuntu package) - addressed in versions 4.3.5-3ubuntu7.3, 4.3.35ubuntu12.10+esm1, 4.4.1-2.1ubuntu5.20.04.2, 4.4.1-2.1ubuntu10.1, 4.4.1-2.2ubuntu6.1
dhcp-common - addressed in versions 4.3.6-40.0.1, 4.3.6-44.0.1
dhcp-server - addressed in versions 4.3.6-40.0.1, 4.3.6-44.0.1
dhcp-relay - addressed in versions 4.3.6-40.0.1, 4.3.6-44.0.1
dhcp-libs - addressed in versions 4.3.6-40.0.1, 4.3.6-44.0.1
dhcp-client - addressed in versions 4.3.6-40.0.1, 4.3.6-44.0.1
dhcp-debugsource - update to 4.4.2-5
dhcp-help - update to 4.4.2-5
dhcp-devel - update to 4.4.2-5
dhcp - update to 4.4.2-5
dhcp-debuginfo - update to 4.4.2-5
dhcp - addressed in versions 4.4.2-9.b1.fc33, 4.4.2-11.b1.fc34
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
SecurID Authentication Manager - update to 8.5 Patch 5
SmartFabric OS10 - update to 10.5.6.1
External References
Related Security Bulletins
- Improper input validation in ISC DHCP
- Input validation error in Cloud Foundry Foundation cflinuxfs3
- Slackware Linux update for dhcp
- Arch Linux update for dhclient
- Arch Linux update for dhcp
- Red Hat Enterprise Linux 7 update for dhcp
- Red Hat Enterprise Linux 8.4 update for dhcp
- CentOS 7 update for dhcp
- Red Hat Enterprise Linux 7.7 update for dhcp
- Red Hat Enterprise Linux 7.4 update for dhcp
- Red Hat Enterprise Linux 7.3 update for dhcp
- Red Hat Enterprise Linux 8.1 update for dhcp
- Red Hat Enterprise Linux 7.2 update for dhcp
- Red Hat Enterprise Linux 8.2 update for dhcp
- Red Hat Enterprise Linux 6 Extended Lifecycle Support update for dhcp
- Red Hat Enterprise Linux 7.6 update for dhcp
- Multiple vulnerabilities in Red Hat Virtualization
- Multiple vulnerabilities in OpenShift Container Platform 4.7
- Amazon Linux AMI update for dhcp
- Multiple vulnerabilities in Dell EMC Unity
- Denial of service in Siemens RUGGEDCOM ROX products
- SUSE update for dhcp
- Ubuntu update for isc-dhcp
- Ubuntu update for isc-dhcp
- Multiple vulnerabilities in IBM Cloud Foundry Migration Runtime
- Input validation error in IBM System Storage TS4500 Tape Library
- Input validation error in IBM i
- Multiple vulnerabilities in Siemens SINEC INS
- SUSE update for dhcp
- SUSE update for dhcp
- Gentoo update for ISC DHCP
- openEuler 20.03 LTS SP1 update for dhcp
- Multiple vulnerabilities in Dell Networking OS10
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in OpenShift Virtualization 2.6
- Fedora 34 update for dhcp
- Fedora 33 update for dhcp
- Anolis OS update for dhcp (Anolis OS 8.2)
- Anolis OS update for dhcp (Anolis OS 8.4)
- PowerProtect Data Protection software update for third-party components
- SecurID Authentication Manager update for third-party components