← Back to CVE List
CVE-2026-3608NVD
Vulnerability Summary
Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving daemon to exit with a stack overflow error.
This issue affects Kea versions 2.6.0 through 2.6.4 and 3.0.0 through 3.0.2.
This issue affects Kea versions 2.6.0 through 2.6.4 and 3.0.0 through 3.0.2.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh
External References
- https://downloads.isc.org/isc/kea/2.6.5
- https://downloads.isc.org/isc/kea/3.0.3
- https://kb.isc.org/docs/cve-2026-3608
- http://www.openwall.com/lists/oss-security/2026/03/25/6
- https://access.redhat.com/errata/RHSA-2026:11344
- https://access.redhat.com/errata/RHSA-2026:7342
- https://access.redhat.com/security/cve/CVE-2026-3608
- https://bugzilla.redhat.com/show_bug.cgi?id=2451139
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3608.json