Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-40779

Опубликовано: 27 авг. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the kea-dhcp4 process will abort with an assertion failure. This happens only if the client request is unicast directly to Kea; broadcast messages do not cause the problem. This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.

A vulnerability was found in Kea. When an attacker who is an existing client with an assigned IP sends a crafted unicast packet directly to the server's IP and Kea cannot find any subnets that match that client's credentials, the server crashes causing a Denial of Service via assertion/NULL-path failure. This vulnerability does not persist for broadcast packets because they ignore such unverifiable clients.

Отчет

This flaw is marked IMPORTANT because a single unicast packet that does not have a subnet match can crash the server, preventing all DHCP clients it serves from obtaining new leases or renewing existing ones until the service is restarted. In this case, Red Hat customers who run Kea service on platforms like RHEL wont be able to access Kea if this vulnerability is triggered. Kea is a DHCP Server that is responsible for assigning IPv4/IPv6 addresses and network parameters to clients. The kea-dhcp4 process handles IPv4 requests, selecting subnets and leases based on client options. This flaw causes kea-dhcp4 to abort after assertion and crash the Kea server if the unicast DHCPv4 request includes certain options that fail subnet selection.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10keaAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2391373kea: Kea crash upon interaction between specific client options and subnet selection

EPSS

Процентиль: 18%
0.00057
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process will abort with an assertion failure. This happens only if the client request is unicast directly to Kea; broadcast messages do not cause the problem. This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.

CVSS3: 7.5
nvd
3 месяца назад

If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process will abort with an assertion failure. This happens only if the client request is unicast directly to Kea; broadcast messages do not cause the problem. This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.

CVSS3: 7.5
debian
3 месяца назад

If a DHCPv4 client sends a request with some specific options, and Kea ...

CVSS3: 7.5
redos
2 месяца назад

Уязвимость kea

CVSS3: 7.5
github
3 месяца назад

If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process will abort with an assertion failure. This happens only if the client request is unicast directly to Kea; broadcast messages do not cause the problem. This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.

EPSS

Процентиль: 18%
0.00057
Низкий

7.5 High

CVSS3