CVE-2026-3608: Stack overflow in Kea daemons
Last updated 8 June 2026
Other sources
Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving daemon to exit with a stack overflow error. This issue affects Kea versions 2.6.0 through 2.6.4 and 3.0.0 through 3.0.2.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/isc-keato a version that resolves this vulnerability.Fixed in 3.0.3-1 - Upgrade
Upgrade
Keato a version that resolves this vulnerability.Fixed in 2.6.5 - Upgrade
Upgrade
Keato a version that resolves this vulnerability.Fixed in 3.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3608?
The severity of CVE-2026-3608 is classified as high due to the potential for a stack overflow that can cause daemon crashes.
How do I fix CVE-2026-3608?
To fix CVE-2026-3608, update your Kea daemons to version 2.6.5 or 3.0.3 or later.
Which versions of Kea are affected by CVE-2026-3608?
CVE-2026-3608 affects Kea versions 2.6.0 through 2.6.4 and 3.0.0 through 3.0.2.
What types of Kea daemons are impacted by CVE-2026-3608?
CVE-2026-3608 impacts the kea-dhcp4, kea-dhcp6, kea-dhcp-ddns, and kea-ctrl-agent daemons.
Can an attacker exploit CVE-2026-3608 remotely?
Yes, an attacker can exploit CVE-2026-3608 remotely by sending a maliciously crafted message over any configured API socket or HA listener.