Opened 7 months ago

Closed 5 weeks ago

#23037 closed enhancement (fixed)

kea-3.2.0

Reported by: Douglas R. Reno Owned by: SecurityAdvisory
Priority: high Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version

This was brought to my attention because it fixes:

"CVE-2026-3608: Stack overflow in Kea daemons ​https://kb.isc.org/docs/cve-2026-3608"

Release notes:

The following changes and bug fixes have been implemented since the
previous release:

1. **Vulnerability**: We addressed an issue, which was assigned
CVE-2026-3608, where a large number of bracket pairs in a JSON payload
directed to any endpoint would result in a stack overflow, due to
recursive calls when parsing the JSON [#4275, #4288, #4387]. Since the
exploit does not require the JSON request to have the full syntax of a
valid command, it bypasses RBAC and the command filters on the
High-Availability endpoints.

2. **Security**: A null dereference is now no longer possible when
configuring the Control Agent with a socket that lacks the mandatory
socket-name entry [#4388, #4365].

3. **Permissions**: UNIX sockets are now created as group-writable
[#4398, #4260]. This allows users belonging to the group to send
commands to the UNIX sockets. In particular, it allows Stork 2.4.0 and
above to detect the Kea daemon.

The issue has been rated as 7.5 High because it allows for remote clients to easily kill the DHCP server serving a network.

Change History (12)

comment:1 by Douglas R. Reno, 7 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:2 by Douglas R. Reno, 4 months ago

Owner: changed from Douglas R. Reno to blfs-book
Status: assigned → new

I'm going to reassign these to the book for now so whoever wants to do them can do them.

In the meantime I will continue working on rivendell, but I do not want to continue holding the project back on important issues.

comment:3 by pierre, 4 months ago

Not sure what has changed, but for both 3.0.2 and 3.0.3, the second sed has to be applied to src/lib/dns/rdataclass.cc too.

Furthermore, the build fails with openssl-4 (or maybe it is just gcc-16 pickyness):

In file included from ../src/lib/asiolink/crypto_tls.h:19,
                 from ../src/lib/asiolink/tls_socket.h:14,
                 from ../src/lib/asiolink/tls_acceptor.h:20,
                 from ../src/lib/tcp/tcp_connection_acceptor.h:11,
                 from ../src/lib/tcp/tcp_connection.h:13,
                 from ../src/lib/tcp/tcp_connection.cc:10:
../src/lib/asiolink/openssl_tls.h: In instantiation of ‘std::string isc::asiolink::TlsStream<Callback>::getSubject() [with Callback = isc::tcp::TcpConnection::SocketCallback; std::string = std::__cxx11::basic_string<char>]’:
../src/lib/asiolink/openssl_tls.h:173:25:   required from here
  173 |     virtual std::string getSubject() {
      |                         ^~~~~~~~~~
../src/lib/asiolink/openssl_tls.h:178:52: error: invalid conversion from ‘const X509_NAME*’ {aka ‘const X509_name_st*’} to ‘X509_NAME*’ {aka ‘X509_name_st*’} [-fpermissive]
  178 |         ::X509_NAME *name = ::X509_get_subject_name(cert);
      |                             ~~~~~~~~~~~~~~~~~~~~~~~^~~~~~
      |                                                    |
      |                 
                                   const X509_NAME* {aka const X509_name_st*}

and similar.

Last edited 4 months ago by pierre (previous) (diff)

comment:4 by pierre, 4 months ago

The X509_xxx error can be fixed with:

sed -e 's/^[ ]*\(::X509_NAME\)/const \1/' \
    -i src/lib/asiolink/openssl_tls.h

comment:5 by Douglas R. Reno, 4 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:6 by Bruce Dubbs, 6 weeks ago

Milestone: 13.1 → 13.2

comment:7 by Bruce Dubbs, 5 weeks ago

Owner: changed from Douglas R. Reno to Bruce Dubbs
Status: assigned → new
Summary: kea-3.0.3 → kea-3.3.1

comment:8 by Bruce Dubbs, 5 weeks ago

Summary: kea-3.3.1 → kea-3.2.0

Back up to version 3.2.0 (stable). Minor versions with odd numbers are development versions.

comment:10 by Bruce Dubbs, 5 weeks ago

Owner: changed from Bruce Dubbs to SecurityAdvisory

Updated at commit 6a1e207995. Leaving open for SA.

comment:11 by Bruce Dubbs, 5 weeks ago

Milestone: 13.2 → 98-Security

comment:12 by Bruce Dubbs, 5 weeks ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.1-001 has been issued.

Note: See TracTickets for help on using tickets.