The vendor explicitly states that these products are not affected by this CVE.
- All currently supported Red Hat products
- Summary
- A flaw was found in wicked, specifically in its DHCPv4 packet capture code. An integer underflow vulnerability exists where the ni_capture_inspect_udp_header() function fails to validate the IP total length field against the IP header length before performing a subtraction. This oversight allows an unauthenticated attacker on the same network to trigger an out-of-bounds read in the wicked DHCPv4 client (wickedd-dhcp4), potentially leading to a daemon crash and a Denial of Service. No information disclosure has been demonstrated as a result of this issue.
- Remediation
- No remediation text is recorded.
