Opened 7 months ago
Closed 5 weeks ago
#23037 closed enhancement (fixed)
kea-3.2.0
| Reported by: | Douglas R. Reno | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version
This was brought to my attention because it fixes:
"CVE-2026-3608: Stack overflow in Kea daemons https://kb.isc.org/docs/cve-2026-3608"
Release notes:
The following changes and bug fixes have been implemented since the previous release: 1. **Vulnerability**: We addressed an issue, which was assigned CVE-2026-3608, where a large number of bracket pairs in a JSON payload directed to any endpoint would result in a stack overflow, due to recursive calls when parsing the JSON [#4275, #4288, #4387]. Since the exploit does not require the JSON request to have the full syntax of a valid command, it bypasses RBAC and the command filters on the High-Availability endpoints. 2. **Security**: A null dereference is now no longer possible when configuring the Control Agent with a socket that lacks the mandatory socket-name entry [#4388, #4365]. 3. **Permissions**: UNIX sockets are now created as group-writable [#4398, #4260]. This allows users belonging to the group to send commands to the UNIX sockets. In particular, it allows Stork 2.4.0 and above to detect the Kea daemon.
The issue has been rated as 7.5 High because it allows for remote clients to easily kill the DHCP server serving a network.
Change History (12)
comment:1 by , 7 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
comment:3 by , 4 months ago
Not sure what has changed, but for both 3.0.2 and 3.0.3, the second sed has to be applied to src/lib/dns/rdataclass.cc too.
Furthermore, the build fails with openssl-4 (or maybe it is just gcc-16 pickyness):
In file included from ../src/lib/asiolink/crypto_tls.h:19,
from ../src/lib/asiolink/tls_socket.h:14,
from ../src/lib/asiolink/tls_acceptor.h:20,
from ../src/lib/tcp/tcp_connection_acceptor.h:11,
from ../src/lib/tcp/tcp_connection.h:13,
from ../src/lib/tcp/tcp_connection.cc:10:
../src/lib/asiolink/openssl_tls.h: In instantiation of ‘std::string isc::asiolink::TlsStream<Callback>::getSubject() [with Callback = isc::tcp::TcpConnection::SocketCallback; std::string = std::__cxx11::basic_string<char>]’:
../src/lib/asiolink/openssl_tls.h:173:25: required from here
173 | virtual std::string getSubject() {
| ^~~~~~~~~~
../src/lib/asiolink/openssl_tls.h:178:52: error: invalid conversion from ‘const X509_NAME*’ {aka ‘const X509_name_st*’} to ‘X509_NAME*’ {aka ‘X509_name_st*’} [-fpermissive]
178 | ::X509_NAME *name = ::X509_get_subject_name(cert);
| ~~~~~~~~~~~~~~~~~~~~~~~^~~~~~
| |
|
const X509_NAME* {aka const X509_name_st*}
and similar.
comment:4 by , 4 months ago
The X509_xxx error can be fixed with:
sed -e 's/^[ ]*\(::X509_NAME\)/const \1/' \
-i src/lib/asiolink/openssl_tls.h
comment:5 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:6 by , 6 weeks ago
| Milestone: | 13.1 → 13.2 |
|---|
comment:7 by , 5 weeks ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
| Summary: | kea-3.0.3 → kea-3.3.1 |
comment:8 by , 5 weeks ago
| Summary: | kea-3.3.1 → kea-3.2.0 |
|---|
Back up to version 3.2.0 (stable). Minor versions with odd numbers are development versions.
comment:9 by , 5 weeks ago
Release notes are at https://downloads.isc.org/isc/kea/3.2.0/Kea-3.2.0-ReleaseNotes.txt
comment:10 by , 5 weeks ago
| Owner: | changed from to |
|---|
Updated at commit 6a1e207995. Leaving open for SA.
comment:11 by , 5 weeks ago
| Milestone: | 13.2 → 98-Security |
|---|
comment:12 by , 5 weeks ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.1-001 has been issued.

I'm going to reassign these to the book for now so whoever wants to do them can do them.
In the meantime I will continue working on rivendell, but I do not want to continue holding the project back on important issues.