Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities Ubuntu Security

USN-8403-1: Kea DHCP vulnerability

  • What: Kea DHCP has a vulnerability that could cause a denial of service
  • Impact: Remote attackers could crash the DHCP server
Read Full Article →

Ubuntu Security Notices USN-8403-1 USN-8403-1: Kea DHCP vulnerability Publication date 8 June 2026 Overview Kea DHCP could be made to crash if it received specially crafted messages. Releases 25.10 24.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages isc-kea - Standards-based DHCP server Details Ali Norouzi discovered that Kea DHCP did not properly handle maliciously crafted messages over configured API sockets and HA listeners. A remote attacker could possibly use this issue to cause Kea DHCP to crash, resulting in a denial of service. Ali Norouzi discovered that Kea DHCP did not properly handle maliciously crafted messages over configured API sockets and HA listeners. A remote attacker could possibly use this issue to cause Kea DHCP to crash, resulting in a denial of service. Update instructions After a standard system update you may need to restart Kea DHCP server instances to make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 25.10 questing kea-admin – 2.6.3-2ubuntu0.1 kea-common – 2.6.3-2ubuntu0.1 kea-dhcp-ddns-server – 2.6.3-2ubuntu0.1 kea-dhcp4-server – 2.6.3-2ubuntu0.1 kea-dhcp6-server – 2.6.3-2ubuntu0.1 24.04 LTS noble kea-admin – 2.4.1-3ubuntu0.2 kea-common – 2.4.1-3ubuntu0.2 kea-dhcp-ddns-server – 2.4.1-3ubuntu0.2 kea-dhcp4-server – 2.4.1-3ubuntu0.2 kea-dhcp6-server – 2.4.1-3ubuntu0.2 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-3608 CVE-2026-3608

Share this article