vulnerability
Oracle Linux: CVE-2025-40779: ELSA-2025-21006: kea security update (IMPORTANT)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:N/I:N/A:C) | Aug 27, 2025 | Dec 5, 2025 | Dec 5, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Aug 27, 2025
Added
Dec 5, 2025
Modified
Dec 5, 2025
Description
If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process will abort with an assertion failure. This happens only if the client request is unicast directly to Kea; broadcast messages do not cause the problem.
This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.
This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.
Solutions
oracle-linux-upgrade-keaoracle-linux-upgrade-kea-docoracle-linux-upgrade-kea-hooksoracle-linux-upgrade-kea-keamaoracle-linux-upgrade-kea-libs
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.