CVE-2025-40779
EUVD-2025-2798127.08.2025, 21:15
If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process will abort with an assertion failure. This happens only if the client request is unicast directly to Kea; broadcast messages do not cause the problem. This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| isc | kea | 2.7.1 ≤ 𝑥 ≤ 2.7.9 | CNA |
| isc | kea | 3.0.0 | CNA |
| isc | kea | 3.1.0 | CNA |
Debian Releases
Common Weakness Enumeration