Page MenuHomeVyOS Platform

CVE-2026-3608: Stack overflow in Kea daemons
Closed, ResolvedPublic

Description

https://kb.isc.org/docs/cve-2026-3608

Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving daemon to exit with a stack overflow error.

It is addressed in https://gitlab.isc.org/isc-projects/kea/-/merge_requests/2983

Details

Version
-
Is it a breaking change?
Perfectly compatible
Issue type
Security vulnerability