ISC Issues Critical Warning Over Kea DHCP Vulnerability That Could Remotely Crash Services
ID: 7ddb316c-1d07-566e-b67f-29d00ccdcebe
STIX ID: report--7ddb316c-1d07-566e-b67f-29d00ccdcebe
Feed Name: GBHackers
Threat Score
A critical stack overflow vulnerability (CVE-2026-3608) in ISC Kea DHCP can be triggered remotely without authentication to crash key daemons and cause complete DHCP outages; affected Kea releases are 2.6.0–2.6.4 and 3.0.0–3.0.2, with patches available in 2.6.5 and 3.0.3 and a recommended TLS (mutual auth) mitigation for those who cannot immediately patch. No active exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
