7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process will abort with an assertion failure. This happens only if the client request is unicast directly to Kea; broadcast messages do not cause the problem.
This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.
This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.
Basic Information
ID
CVE-2025-40779
Source
isc
Published
Aug 27, 2025 at 20:23
Affected Product
Vendor
ISC
Product
Kea
Version
2.7.1
Affected Versions
ISC Kea 2.7.1
ISC Kea 3.0.0
ISC Kea 3.1.0
ISC Kea 3.0.0
ISC Kea 3.1.0