CVE-2015-8605: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 82.7% chance of exploitation in the next 30 days.

ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only; version 15.10 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • ISC Dhcp: version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.1-esv only; version 4.1.0 only; …
  • Sophos Unified Threat Management UP2DATE: up to and including 9.318; up to and including 9.353

Published 2016-01-14. Last modified 2026-06-17.