If a DHCPv4 client sends a request with some specific...
High severity
Unreviewed
Published
Aug 27, 2025
to the GitHub Advisory Database
•
Updated Aug 27, 2025
Description
Published by the National Vulnerability Database
Aug 27, 2025
Published to the GitHub Advisory Database
Aug 27, 2025
Last updated
Aug 27, 2025
If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the
kea-dhcp4
process will abort with an assertion failure. This happens only if the client request is unicast directly to Kea; broadcast messages do not cause the problem.This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.
References