Failure to properly clean up closed OMAPI connections can exhaust available sockets
35Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3epss 73%
probabilidad de explotación
73%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
Lo que declaran los fabricantes (VEX)
Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.
Red Hatdocumento VEX ↗
Corregido
10 productos (92 componentes)
Red Hat Enterprise Linux Server (v. 7) · Red Hat Enterprise Linux Server Optional (v. 7) · Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) · Red Hat Enterprise Linux Workstation (v. 7) · Red Hat Enterprise Linux Client (v. 7) · y otros 5
No afectado
2 productos (6 componentes) — porque el código vulnerable no está presente en el producto
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 5
A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected but are well beyond their end-of-life (EOL). Releases prior to 4.1.0 have not been tested.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Productos afectados
ISC · ISC DHCP