https://seclists.org/oss-sec/2025/q2/177: ISC has disclosed the vulnerabilities in Kea (CVE-2025-32801, CVE-2025-32802, CVE-2025-32803)
Published May 28, 2025
·Updated
Affected Software
1 affected component
Internet Systems Consortium Kea DHCP
Frequently Asked Questions
1
What is the severity of CVE-2025-32801?
CVE-2025-32801 has a high severity level due to its potential for local root exploitation.
2
How do I fix CVE-2025-32801?
To fix CVE-2025-32801, upgrade to the latest version of the ISP Kea DHCP server that contains the security patch.
3
What does CVE-2025-32802 involve?
CVE-2025-32802 involves local vulnerabilities that can affect the REST API and potentially lead to unauthorized access.
4
What impact does CVE-2025-32803 have on the Kea DHCP server?
CVE-2025-32803 can lead to privilege escalation in the Kea DHCP server environment, further compromising system integrity.
5
Is it necessary to update for all CVE-2025 vulnerabilities?
Yes, it is recommended to update for all CVE-2025 vulnerabilities to ensure the security and stability of the Kea DHCP server.