CVE-2026-3608

Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving daemon to exit with a stack overflow error. This issue affects Kea versions 2.6.0 through 2.6.4 and 3.0.0 through 3.0.2.
Configurations

No configuration.

History

30 Jun 2026, 03:19

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:11344 -
  • () https://access.redhat.com/errata/RHSA-2026:7342 -
  • () https://access.redhat.com/security/cve/CVE-2026-3608 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2451139 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3608.json -

17 Jun 2026, 10:43

Type Values Removed Values Added
Summary
  • (es) Enviar un mensaje diseñado maliciosamente a los demonios kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4 o kea-dhcp6 a través de cualquier socket API o oyente HA configurado puede provocar que el demonio receptor se cierre con un error de desbordamiento de pila. Este problema afecta a las versiones de Kea 2.6.0 a 2.6.4 y 3.0.0 a 3.0.2.

25 Mar 2026, 18:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/03/25/6 -

25 Mar 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 09:16

Updated : 2026-07-15 02:21


NVD link : CVE-2026-3608

Mitre link : CVE-2026-3608

CVE.ORG link : CVE-2026-3608


JSON object : View

Products Affected

No product.

CWE
CWE-617

Reachable Assertion