REDHAT-BUG-2451139: High severity ISC kea vulnerability
Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving daemon to exit with a stack overflow error. This issue affects Kea versions 2.6.0 through 2.6.4 and 3.0.0 through 3.0.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2451139?
The severity of REDHAT-BUG-2451139 is high due to the potential for a stack overflow that could lead to daemon crashes.
How do I fix REDHAT-BUG-2451139?
To fix REDHAT-BUG-2451139, upgrade the ISC Kea software to version 2.6.5 or 3.0.3 or later.
Which versions of ISC Kea are affected by REDHAT-BUG-2451139?
ISC Kea versions 2.6.0 through 2.6.4 and 3.0.0 through 3.0.2 are affected by REDHAT-BUG-2451139.
What causes the issue in REDHAT-BUG-2451139?
The issue in REDHAT-BUG-2451139 is caused by sending a maliciously crafted message to the kea-ctrl-agent or other related daemons.
Is a workaround available for REDHAT-BUG-2451139?
No official workaround is provided for REDHAT-BUG-2451139; the only mitigation is to upgrade to a fixed version.