CVE-2025-11232
To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default); and "ddns-qualifying-suffix" must *NOT* be empty (the default is empty). DDNS updates do not need to be enabled for this issue to manifest. A client that sends certain option content would then cause kea-dhcp4 to exit unexpectedly. This issue affects Kea versions 3.0.1 through 3.0.1 and 3.1.1 through 3.1.2.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.40%
- CWE
- CWE-823
- Published
- 2025-10-29
- Last modified
- 2026-03-12
Affected products
- ISC Kea
- ISC Kea
- ISC Kea
- ISC Kea
- ISC Kea
- ISC Kea
Weakness type
Related vulnerabilities
- CVE-2026-31912 — OOBR in libpcap before 1.10.7
- CVE-2026-45199 — GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers
- CVE-2026-72642 — Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference Process
- CVE-2026-49746 — GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem
- CVE-2026-49745 — GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0
- CVE-2026-49744 — GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex()
- CVE-2026-21734 — GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation
- CVE-2026-34193 — GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr()