If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process will abort with an assertion failure. This happens only if the client request is unicast directly to Kea; broadcast messages do not cause the problem. This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade keaUpgrade kea-devel | Dec 10, 2025 | Aug 27, 2025 |
| Oracle_linux | — | Upgrade kea-libsUpgrade kea-keamaUpgrade kea-hooksUpgrade keaUpgrade kea-doc | Dec 5, 2025 | Aug 27, 2025 |
| Redhat_linux | — | Upgrade kea-devel-debuginfoUpgrade kea-keama-debuginfoUpgrade kea-debugsourceUpgrade kea-docUpgrade kea-libsUpgrade kea-libs-debuginfoUpgrade kea-hooks-debuginfoUpgrade kea-debuginfoUpgrade kea-keamaUpgrade kea-hooksUpgrade kea | Jan 27, 2026 | Aug 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub