CVE-2025-40779
27.08.2025, 21:15
If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process will abort with an assertion failure. This happens only if the client request is unicast directly to Kea; broadcast messages do not cause the problem. This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.

Debian Releases
Common Weakness Enumeration
References