CVE-2019-6470
published 2019-11-01CVE-2019-6470: There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
8.81%
94.6th percentile
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC contain copies of this, and other, BIND libraries in combinations that have been tested prior to release and are known to not present issues like this. Some third-party packagers of ISC software have modified the dhcpd source, BIND source, or version matchup in ways that create the crash potential. Based on reports available to ISC, the crash probability is large and no analysis has been done on how, or even if, the probability can be manipulated by an attacker. Affects: Builds of dhcpd versions prior to version 4.4.1 when using BIND versions 9.11.2 or later, or BIND versions with specific bug fixes backported to them. ISC does not have access to comprehensive version lists for all repackagings of dhcpd that are vulnerable. In particular, builds from other vendors may also be affected. Operators are advised to consult their vendor documentation.
Affected
81 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | isc-dhcp | < isc-dhcp 4.4.1-2 (bookworm) | isc-dhcp 4.4.1-2 (bookworm) |
| isc | dhcpd | < 4.4.1 | 4.4.1 |
| msrc | azl3_bind_9.16.44-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_bind_9.20.5-4_on_azure_linux_3.0 | — | — |
| msrc | bind-9.16.15-4.cm2.aarch64.rpm | — | — |
| msrc | bind-9.16.15-4.cm2.x86_64.rpm | — | — |
| msrc | bind-9.19.21-1.azl3.aarch64.rpm | — | — |
| msrc | bind-9.19.21-1.azl3.x86_64.rpm | — | — |
| msrc | bind-chroot-9.16.15-4.cm2.aarch64.rpm | — | — |
| msrc | bind-chroot-9.16.15-4.cm2.x86_64.rpm | — | — |
| msrc | bind-chroot-9.19.21-1.azl3.aarch64.rpm | — | — |
| msrc | bind-chroot-9.19.21-1.azl3.x86_64.rpm | — | — |
| msrc | bind-debuginfo-9.16.15-1.cm1.aarch64.rpm | — | — |
| msrc | bind-debuginfo-9.16.15-1.cm1.x86_64.rpm | — | — |
| msrc | bind-debuginfo-9.16.15-4.cm2.aarch64.rpm | — | — |
| msrc | bind-debuginfo-9.16.15-4.cm2.x86_64.rpm | — | — |
| msrc | bind-devel-9.16.15-4.cm2.aarch64.rpm | — | — |
| msrc | bind-devel-9.16.15-4.cm2.x86_64.rpm | — | — |
| msrc | bind-devel-9.19.21-1.azl3.aarch64.rpm | — | — |
| msrc | bind-devel-9.19.21-1.azl3.x86_64.rpm | — | — |
| msrc | bind-dlz-filesystem-9.16.15-4.cm2.aarch64.rpm | — | — |
| msrc | bind-dlz-filesystem-9.16.15-4.cm2.x86_64.rpm | — | — |
| msrc | bind-dlz-filesystem-9.19.21-1.azl3.aarch64.rpm | — | — |
| msrc | bind-dlz-filesystem-9.19.21-1.azl3.x86_64.rpm | — | — |
| msrc | cbl2_bind_9.16.15-3_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
dhcpd: use-after-free error leads crash in IPv6 mode when using mismatched BIND libraries
vendor_msrc·2019-11-12·CVSS 7.5
CVE-2019-6470 [MEDIUM] dhcpd: use-after-free error leads crash in IPv6 mode when using mismatched BIND libraries
dhcpd: use-after-free error leads crash in IPv6 mode when using mismatched BIND libraries
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
isc: isc
Customer Action Required: Yes
Remediation: CBL-Mariner Rele
Ubuntu
DHCP vulnerability
vendor_ubuntu·2019-05-13
CVE-2019-6470 DHCP vulnerability
Title: DHCP vulnerability
Summary: DHCP could be made to crash if it received specially crafted network
traffic.
It was discovered that DHCP, when built with a mismatched external BIND
library, incorrectly handled certain memory operations. A remote attacker
could possibly use this issue to cause DHCP to crash, resulting in a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-6470: isc-dhcp - There had existed in one of the ISC BIND libraries a bug in a function that was ...
vendor_debian·2019·CVSS 6.5
CVE-2019-6470 [MEDIUM] CVE-2019-6470: isc-dhcp - There had existed in one of the ISC BIND libraries a bug in a function that was ...
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC contain copies of this, and other, BIND libraries in combinations that have been tested prior to release and are known to not present issues like this. Some third-party packagers of ISC software have modified the dhcpd source, BIND source, or version matchup in ways that create the crash potential. Based on reports available to ISC, the crash probability is large and no analysis has been done on how, or even if, the probability can be manipulated by an attacker. Affects: Buil
Red Hat
dhcp: double-deletion of the released addresses in the dhcpv6 code leading to crash and possible DoS
vendor_redhat·2018-07-14·CVSS 6.5
CVE-2019-6470 [MEDIUM] CWE-20 dhcp: double-deletion of the released addresses in the dhcpv6 code leading to crash and possible DoS
dhcp: double-deletion of the released addresses in the dhcpv6 code leading to crash and possible DoS
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC contain copies of this, and other, BIND libraries in combinations that have been tested prior to release and are known to not present issues like this. Some third-party packagers of ISC software have modified the dhcpd source, BIND source, or version matchup in ways that create the crash potential. Based on reports available to ISC, the crash probability is large and no analy
GHSA
GHSA-w4w8-43xj-r4wr: There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode
ghsa_unreviewed·2022-05-24
CVE-2019-6470 [HIGH] GHSA-w4w8-43xj-r4wr: There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC contain copies of this, and other, BIND libraries in combinations that have been tested prior to release and are known to not present issues like this. Some third-party packagers of ISC software have modified the dhcpd source, BIND source, or version matchup in ways that create the crash potential. Based on reports available to ISC, the crash probability is large and no analysis has been done on how, or even if, the probability can be manipulated by an attacker. Affects: Buil
OSV
CVE-2019-6470: There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode
osv·2019-11-01·CVSS 7.5
CVE-2019-6470 [HIGH] CVE-2019-6470: There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC contain copies of this, and other, BIND libraries in combinations that have been tested prior to release and are known to not present issues like this. Some third-party packagers of ISC software have modified the dhcpd source, BIND source, or version matchup in ways that create the crash potential. Based on reports available to ISC, the crash probability is large and no analysis has been done on how, or even if, the probability can be manipulated by an attacker. Affects: Buil
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-6470 dhcp: double-deletion of the released addresses in the dhcpv6 code leading to crash and possible DoS [fedora-all]
bugzilla·2019-05-10·CVSS 6.5
CVE-2019-6470 [MEDIUM] CVE-2019-6470 dhcp: double-deletion of the released addresses in the dhcpv6 code leading to crash and possible DoS [fedora-all]
CVE-2019-6470 dhcp: double-deletion of the released addresses in the dhcpv6 code leading to crash and possible DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NO
Bugzilla
CVE-2019-6470 dhcp: double-deletion of the released addresses in the dhcpv6 code leading to crash and possible DoS
bugzilla·2019-05-10·CVSS 6.5
CVE-2019-6470 [MEDIUM] CVE-2019-6470 dhcp: double-deletion of the released addresses in the dhcpv6 code leading to crash and possible DoS
CVE-2019-6470 dhcp: double-deletion of the released addresses in the dhcpv6 code leading to crash and possible DoS
Double-deletion of the released addresses in the dhcpv6 code leading to crash and possible DoS. This issue was introduced by a commit which fixes a bug in the ISC heap library.
Discussion:
Created dhcp tracking bugs for this issue:
Affects: fedora-all [bug 1708642]
---
This flaw is in the dhcp server code (binary package dhcp), client-side code is not affected.
---
Upstream patch:
https://source.isc.org/cgi-bin/gitweb.cgi?p=dhcp.git;a=commit;h=abacf8ad0d8844685e5cd76645a34ef2b8da3253
---
External References:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=896122
---
Another reference:
https://bugzilla.redhat.com/show_bug.cgi?id=1641246
---
This issue has been
https://access.redhat.com/errata/RHSA-2019:2060https://access.redhat.com/errata/RHSA-2019:3525https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=896122https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00048.htmlhttps://lists.opensuse.org/opensuse-security-announce/2019-10/msg00049.htmlhttps://access.redhat.com/errata/RHSA-2019:2060https://access.redhat.com/errata/RHSA-2019:3525https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=896122https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00048.htmlhttps://lists.opensuse.org/opensuse-security-announce/2019-10/msg00049.html
2019-11-01
Published