CVE-2022-0324 - CVE House
Back to Database
Status published High CVE-2022-0324

Buffer Overflow in Dhcp6relay in Software for Open Networking in the Cloud (SONiC)

Vulnerability Description

There is a vulnerability in DHCPv6 packet parsing code that could be explored by remote attacker to craft a packet that could cause buffer overflow in a memcpy call, leading to out-of-bounds memory write that would cause dhcp6relay to crash. Dhcp6relay is a critical process and could cause dhcp relay docker to shutdown. Discovered by Eugene Lim of GovTech Singapore.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-0324

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Linux Foundation

View all reports →

Affected Software

Software for Open Networking in the Cloud (SONiC)
Vulnerable Versions:
202111

Timeline

Official Publish: November 14th, 2022
Last Modified: April 30th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Weaknesses (CWE)