#22326 closed enhancement (fixed)
kea-3.0.2
| Reported by: | Joe Locash | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
Fixes CVE-2025-11232: Invalid characters cause assert
Rated high.
Change History (5)
comment:1 by , 11 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 10 months ago
This update is... a bit complicated.
I've updated the book to 3.0.2 at a081f171b1a5aa3ffb8f291533e43d99e1696db7
I had to update the systemd units because they had several bugs including removing /run/kea anytime one of the four services stopped.
After getting that going though, I decided to take a look at the SysV version... and have discovered that the bootscripts can't work in their current state. One of the problems is ordering since we are using dhcp_ddns by default, and that requires named. There is also support for postgresql and mariadb, and Kea gets started before those are up. Kea is also brought up in rc1, where there is no network.
In addition, the bootscript for Kea runs /usr/sbin/keactrl - which references /etc/kea/keactrl, and uses /usr/etc for reading configuration files.
I am starting up a build of SysV with jhalfs right now on the same VM I did this for systemd on, but am going to go work on other tickets while that is building.
I do not feel comfortable filing a security advisory for this until the bootscripts are fixed, so this ticket probably won't be closed for another day or two.
comment:4 by , 10 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
SA-12.4-061 issued.
Fixed the problems with Kea on SysV at ea498a7c990fafe8a0000541101184928ed64987 and fixed building it with Boost 1.90.0 at 76460ef10a3a2e9c1ee234c98111fbe8204c6172
