Search CVE reports


Toggle filters

1 – 8 of 8 results


CVE-2025-40779

Medium priority
Needs evaluation

If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process will abort with an assertion failure. This happens only if the client request is...

1 affected package

isc-kea

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-kea Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-32803

Medium priority
Vulnerable

In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.

1 affected package

isc-kea

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-kea Vulnerable Not affected Not affected Not affected
Show less packages

CVE-2025-32802

Medium priority
Vulnerable

Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the...

1 affected package

isc-kea

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-kea Vulnerable Not affected Not affected Not affected
Show less packages

CVE-2025-32801

Medium priority
Vulnerable

Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in...

1 affected package

isc-kea

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-kea Vulnerable Not affected Not affected Not affected
Show less packages

CVE-2019-6474

Medium priority
Ignored

A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases which are rejected as invalid when the server tries to load leases from storage on restart. If...

1 affected package

isc-kea

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-kea Not affected Not affected Not affected Ignored
Show less packages

CVE-2019-6473

Medium priority

Some fixes available 2 of 7

An invalid hostname option can trigger an assertion failure in the Kea DHCPv4 server process (kea-dhcp4), causing the server process to exit. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.

1 affected package

isc-kea

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-kea Not affected Not affected Not affected Fixed
Show less packages

CVE-2019-6472

Medium priority
Ignored

A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.

1 affected package

isc-kea

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-kea Not affected Not affected Not affected Ignored
Show less packages

CVE-2018-5739

Medium priority
Ignored

An extension to hooks capabilities which debuted in Kea 1.4.0 introduced a memory leak for operators who are using certain hooks library facilities. In order to support multiple requests simultaneously, Kea 1.4 added a callout...

1 affected package

isc-kea

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-kea Not affected Not affected Not affected
Show less packages