CVE-2026-3608 Details
Description
Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving daemon to exit with a stack overflow error. This issue affects Kea versions 2.6.0 through 2.6.4 and 3.0.0 through 3.0.2.
A stack overflow vulnerability has been identified in ISC Kea DHCP versions 2.6.0 prior to 2.6.4 and 3.0.0 prior to 3.0.2. This vulnerability affects the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, and kea-dhcp6 daemons. When a maliciously crafted message is sent over any configured API socket or high-availability listener, the receiving daemon can crash due to the stack overflow error.
Users can upgrade to Kea versions 2.6.5 or 3.0.3 to address this vulnerability. For those using versions 2.6.0 through 2.6.4 or 3.0.0 through 3.0.2, upgrading to the latest version is recommended. After upgrading, ensure that API sockets are secured with TLS and that mutual authentication is enabled, requiring clients to present a certificate.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-617 | Reachable Assertion | redhat-SADP |
| CWE-617 | Reachable Assertion | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 25, 2026 | CVE Modified | CVE |
| Mar 25, 2026 | New CVE Received | [email protected] |