PT-2025-44333 · Kea+2 · Kea+2
Published
2025-10-29
·
Updated
2026-04-01
·
CVE-2025-11232
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Kea versions 3.0.1 through 3.0.1
Kea versions 3.1.1 through 3.1.2
Description
The software can exit unexpectedly when receiving certain option content from a client if three configuration parameters are set to specific values. Specifically, the
hostname-char-set parameter must be at its default setting of '[^A-Za-z0-9.-]', the hostname-char-replacement parameter must be empty (the default), and the ddns-qualifying-suffix parameter must not be empty (the default is empty). Dynamic DNS updates do not need to be enabled for this to occur.Recommendations
Ensure the
ddns-qualifying-suffix parameter is empty for Kea versions 3.0.1 through 3.0.1.
Ensure the ddns-qualifying-suffix parameter is empty for Kea versions 3.1.1 through 3.1.2.Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Kea
Red Os