7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default); and "ddns-qualifying-suffix" must *NOT* be empty (the default is empty). DDNS updates do not need to be enabled for this issue to manifest. A client that sends certain option content would then cause kea-dhcp4 to exit unexpectedly.
This issue affects Kea versions 3.0.1 through 3.0.1 and 3.1.1 through 3.1.2.
This issue affects Kea versions 3.0.1 through 3.0.1 and 3.1.1 through 3.1.2.
Basic Information
ID
CVE-2025-11232
Source
isc
Published
Oct 29, 2025 at 18:02
Modified
Oct 29, 2025 at 18:22
Affected Product
Vendor
ISC
Product
Kea
Version
3.0.1
Affected Versions
ISC Kea 3.0.1
ISC Kea 3.1.1
ISC Kea 3.1.1