logo

ISC Issues Critical Warning Over Kea DHCP Vulnerability That Could Remotely Crash Services

ID: 7ddb316c-1d07-566e-b67f-29d00ccdcebe

STIX ID: report--7ddb316c-1d07-566e-b67f-29d00ccdcebe

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-03-27

Date Updated: 2026-04-22

Author: Divya

...
...

A critical stack overflow vulnerability (CVE-2026-3608) in ISC Kea DHCP can be triggered remotely without authentication to crash key daemons and cause complete DHCP outages; affected Kea releases are 2.6.0–2.6.4 and 3.0.0–3.0.2, with patches available in 2.6.5 and 3.0.3 and a recommended TLS (mutual auth) mitigation for those who cannot immediately patch. No active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.