CVE-2025-11232 Details
Description
To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default); and "ddns-qualifying-suffix" must *NOT* be empty (the default is empty). DDNS updates do not need to be enabled for this issue to manifest. A client that sends certain option content would then cause kea-dhcp4 to exit unexpectedly. This issue affects Kea versions 3.0.1 through 3.0.1 and 3.1.1 through 3.1.2.
A denial-of-service vulnerability has been identified in ISC Kea versions 3.0.1 and 3.1.1 through 3.1.2. The issue arises in the Kea DHCPv4 server when specific configuration parameters are set in a certain way. To trigger the vulnerability, the 'hostname-char-set' must be left at its default value, the 'hostname-char-replacement' must be empty, and the 'ddns-qualifying-suffix' must not be empty. When these conditions are met, a client can send certain option content that causes the kea-dhcp4 server to exit unexpectedly.
Users can upgrade to Kea versions 3.0.2 or 3.1.3 to address this vulnerability. As an alternative workaround, the 'hostname-char-replacement' option can be set to any value other than empty, such as 'x'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 29, 2025CISA-ADP
Assessed Oct 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/10/29/5 | CVE | |
| https://kb.isc.org/docs/cve-2025-11232 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-823 | Use of Out-of-range Pointer Offset | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ISC Kea | 3.0.1 (semver) 3.1.1 (semver) 3.1.2 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | CVE Modified | CVE |
| Oct 29, 2025 | New CVE Received | [email protected] |
Volerion