﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
23037	kea-3.2.0	Douglas R. Reno	SecurityAdvisory	"New point version

This was brought to my attention because it fixes:

""CVE-2026-3608:        Stack overflow in Kea daemons https://kb.isc.org/docs/cve-2026-3608""

Release notes:

{{{

The following changes and bug fixes have been implemented since the
previous release:

1. **Vulnerability**: We addressed an issue, which was assigned
CVE-2026-3608, where a large number of bracket pairs in a JSON payload
directed to any endpoint would result in a stack overflow, due to
recursive calls when parsing the JSON [#4275, #4288, #4387]. Since the
exploit does not require the JSON request to have the full syntax of a
valid command, it bypasses RBAC and the command filters on the
High-Availability endpoints.

2. **Security**: A null dereference is now no longer possible when
configuring the Control Agent with a socket that lacks the mandatory
socket-name entry [#4388, #4365].

3. **Permissions**: UNIX sockets are now created as group-writable
[#4398, #4260]. This allows users belonging to the group to send
commands to the UNIX sockets. In particular, it allows Stork 2.4.0 and
above to detect the Kea daemon.
}}}

The issue has been rated as 7.5 High because it allows for remote clients to easily kill the DHCP server serving a network."	enhancement	closed	high	98-Security	BOOK	git	medium	fixed		
