Failure to properly clean up closed OMAPI connections can exhaust available sockets
35Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 73%
exploitation probability
73%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Fixed
10 products (92 components)
Red Hat Enterprise Linux Server (v. 7) · Red Hat Enterprise Linux Server Optional (v. 7) · Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) · Red Hat Enterprise Linux Workstation (v. 7) · Red Hat Enterprise Linux Client (v. 7) · and others 5
Not affected
2 products (6 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 5
A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected but are well beyond their end-of-life (EOL). Releases prior to 4.1.0 have not been tested.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products
ISC · ISC DHCP