vulnerability

Oracle Linux: CVE-2025-40779: ELSA-2025-21006: kea security update (IMPORTANT)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Aug 27, 2025
Added
Dec 5, 2025
Modified
Dec 5, 2025

Description

If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process will abort with an assertion failure. This happens only if the client request is unicast directly to Kea; broadcast messages do not cause the problem.
This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.

Solutions

oracle-linux-upgrade-keaoracle-linux-upgrade-kea-docoracle-linux-upgrade-kea-hooksoracle-linux-upgrade-kea-keamaoracle-linux-upgrade-kea-libs
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.