https://seclists.org/oss-sec/2026/q1/384: ISC has disclosed one vulnerability in Kea (CVE-2026-3608)
Published Mar 25, 2026
·Updated
Affected Software
1 affected component
Internet Systems Consortium Kea
Frequently Asked Questions
1
What is the severity of CVE-2026-3608?
CVE-2026-3608 has been assigned a severity level that indicates it poses a significant risk to the security of the ISC Kea software.
2
How do I fix CVE-2026-3608?
To fix CVE-2026-3608, you should upgrade to the latest versions of ISC Kea, specifically 2.6.5 or 3.0.3.
3
What versions of Kea are affected by CVE-2026-3608?
CVE-2026-3608 affects specific older versions of the ISC Kea software, requiring an update to mitigate the risk.
4
When was CVE-2026-3608 disclosed?
CVE-2026-3608 was disclosed on March 25, 2026.
5
Who disclosed CVE-2026-3608?
CVE-2026-3608 was disclosed by the Internet Systems Corporation.