CVE-2019-6470
dhcpd: use-after-free error leads crash in IPv6 mode when using mismatched BIND libraries
Public exploit available. Not confirmed exploited in the wild yet. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
What it is
From the CVE record
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC contain copies of this, and other, BIND libraries in combinations that have been tested prior to release and are known to not present issues like this. Some third-party packagers of ISC software have modified the dhcpd source, BIND source, or version matchup in ways that create the crash potential. Based on reports available to ISC, the crash probability is large and no analysis has been done on how, or even if, the probability can be manipulated by an attacker. Affects: Builds of dhcpd versions prior to version 4.4.1 when using BIND versions 9.11.2 or later, or BIND versions with specific bug fixes backported to them. ISC does not have access to comprehensive version lists for all repackagings of dhcpd that are vulnerable. In particular, builds from other vendors may also be affected. Operators are advised to consult their vendor documentation.
In plain language
No plain-language summary for this CVE yet.
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Not in the catalog. CISA has not confirmed exploitation.
- Public exploits
1 source with a proof of concept or module.
Exploit links, PoCs and Metasploit modules after sign-in- EPSS
8.8% chance of exploitation activity in the next 30 days, which ranks it in the 95th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
The patch came 329 days before any public exploit.
- OpenVAS check added
- Public exploit / PoCsource: other
- Patch availablerecord updated
- Publishedweakness classified
Affected products
- Red Hat Enterprise LinuxOperating Systems / linux-distro
- enterprise linux for arm 64Operating Systems / linux-distro
- enterprise linux for arm 64 eusOperating Systems / linux-distro
- enterprise linux for ibm z systemsOperating Systems / linux-distro
- enterprise linux for ibm z systems eusOperating Systems / linux-distro
- enterprise linux for power big endianOperating Systems / linux-distro
- enterprise linux for power little endianOperating Systems / linux-distro
- enterprise linux for power little endian eusOperating Systems / linux-distro
- Suse Linux Enterprise DesktopOperating Systems / linux-distro
- SUSE Linux Enterprise Server for SAP ApplicationsOperating Systems / linux-distro
- SUSE Linux Enterprise Software Development KitOperating Systems / linux-distro
- OpenSUSE LeapOperating Systems / linux-distro
- SUSE Linux Enterprise Module for BasesystemOperating Systems / linux-distro
- SUSE CaaS PlatformOperating Systems / linux-distro
- SUSE Linux Enterprise Module for Development ToolsOperating Systems / linux-distro
- SUSE Linux Enterprise Module for Server ApplicationsOperating Systems / linux-distro
And 12 more affected products. See all after sign-in
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Scored 6.5 by NVD.
How it is reached
- Attack Vector AdjacentRequires access to the local network (e.g. same Wi-Fi, Bluetooth)
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality NoneNo confidentiality impact
- Integrity NoneNo integrity impact
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
Sources
References in the record
- access.redhat.com/errata/RHSA-2019:2060
- access.redhat.com/errata/RHSA-2019:3525
- bugs.debian.org/cgi-bin/bugreport.cgi?bug=896122
And 10 more references. See all after sign-in
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Red Hat Enterprise Linux, not every advisory. This one: public exploit.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI