PT-2025-34937 · Kea+2 · Kea+2
Published
2025-01-01
·
Updated
2026-03-11
·
CVE-2025-40779
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Kea versions 2.7.1 through 2.7.9
Kea version 3.0.0
Kea version 3.1.0
Description:
If a DHCPv4 client sends a request with specific options and Kea fails to find an appropriate subnet for the client, the
kea-dhcp4 process will abort with an assertion failure. This issue occurs only when the client request is unicast directly to Kea; broadcast messages do not cause the problem. A malicious or misconfigured DHCP client can crash the Kea DHCPv4 service by sending a single packet.Recommendations:
Update Kea to a version later than 3.1.0.
Fix
NULL Pointer Dereference
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Kea
Red Os