Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-25217

27
FAUCET Score

CVE-2021-25217 is a vulnerability in ISC DHCP, affecting versions 4.1-ESV-R1 through 4.1-ESV-R16 and 4.4.0 through 4.4.2, which can lead to denial of service or data loss. Specifically, a crafted lease file can cause dhclient to crash on 32-bit systems, or dhcpd to crash and improperly delete lease entries, particularly on 32-bit architectures or without specific compiler flags. This vulnerability is rated High severity (CVSS 7.4), with an attack vector of Adjacent Network, Low attack complexity, and no user interaction required. The primary impact is High availability loss, as affected DHCP services or clients can cease operation, and in some dhcpd configurations, lease data can be deleted. There is currently no evidence of active exploitation, nor are there publicly available exploit codes in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.4, < 4.4.2-P1CPE match
cpe:2.3:a:isc:dhcpd:*:*:*:*:*:*:*:*
>= 4.4.0, <= 4.4.2CPE matchmatch criteria
cpe:2.3:a:isc:dhcp:*:*:*:*:*:*:*:*
4.1-esvCPE matchmatch criteria
cpe:2.3:a:isc:dhcp:4.1-esv:r1:*:*:*:*:*:*
4.1-esvCPE matchmatch criteria
cpe:2.3:a:isc:dhcp:4.1-esv:r10:*:*:*:*:*:*
4.1-esvCPE matchmatch criteria
cpe:2.3:a:isc:dhcp:4.1-esv:r10_b1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
6.12%
Probability of exploitation in next 30 days
EPSS Percentile
92.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0612 is in the 96th percentile among its peer group of 1,859 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (24)

microsoftpatch availablevia msrc
Product: 19047-16820Fixed in: 4.4.2-2
microsoftpatch availablevia msrc
Product: 19048-16823Fixed in: 4.4.2-4
microsoftpatch availablevia msrc
Product: cm1 dhcp 4.4.2-2 on CBL Mariner 1.0Fixed in: 4.4.2-2
microsoftpatch availablevia msrc
Product: cbl2 dhcp 4.4.2-4 on CBL Mariner 2.0Fixed in: 4.4.2-4
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Advanced Update SupportFixed in: dhcp-12:4.2.5-42.el7_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Advanced Update SupportFixed in: dhcp-12:4.2.5-47.el7_3.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: dhcp-12:4.2.5-58.el7_4.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Telco Extended Update SupportFixed in: dhcp-12:4.2.5-58.el7_4.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsFixed in: dhcp-12:4.2.5-58.el7_4.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Advanced Update Support(Disable again in 2026 - SPRHEL-7118)Fixed in: dhcp-12:4.2.5-69.el7_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Telco Extended Update SupportFixed in: dhcp-12:4.2.5-69.el7_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Update Services for SAP SolutionsFixed in: dhcp-12:4.2.5-69.el7_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Extended Update SupportFixed in: dhcp-12:4.2.5-77.el7_7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: dhcp-12:4.3.6-44.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Extended Update SupportFixed in: dhcp-12:4.3.6-34.el8_1.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: dhcp-12:4.3.6-40.el8_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: cri-o-0:1.20.3-6.rhaos4.7.git0d0f863.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: dhcp-12:4.3.6-41.el8_3.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: openshift-clients-0:4.7.0-202106252127.p0.git.8b4b094.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: openshift-kuryr-0:4.7.0-202106232224.p0.git.c7654fb.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: polkit-0:0.115-11.el8_3.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Fixed in: redhat-virtualization-host-0:4.3.16-20210615.0.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 Extended Lifecycle SupportFixed in: dhcp-12:4.1.1-64.P1.el6_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: dhcp-12:4.2.5-83.el7_9.1
View patch

Vendor Advisories (2)

redhatCVE-2021-25217Important

dhcp: stack-based buffer overflow when parsing statements with colon-separated hex digits in config or lease files in dhcpd and dhclient

May 26, 2021
microsoft2021-May/CVE-2021-25217Important

A buffer overrun in lease file parsing code can be used to exploit a common vulnerability shared by dhcpd and dhclient

May 11, 2021

References

cert-portal.siemens.com / productcert/pdf/ssa-406691.pdf
PatchThird Party Advisory
cert-portal.siemens.com / productcert/pdf/ssa-637483.pdf
PatchThird Party Advisory
kb.isc.org / docs/cve-2021-25217
ExploitVendor Advisory
lists.debian.org / debian-lts-announce/2021/06/msg00002.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/5QI4DYC7J4BGHEW3NH4XHMWTHYC36UK4
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/Z2LB42JWIV4M4WDNXX5VGIP26FEYWKIF
security.gentoo.org / glsa/202305-22
security.netapp.com / advisory/ntap-20220325-0011
Third Party Advisory
openwall.com / lists/oss-security/2021/05/26/6
Mailing ListPatchThird Party Advisory