🛡️ openSUSE-SU-2026:20452-1 — kea (CVE-2025-11232 +1 more)
Description
Security update for kea
This update for kea fixes the following issues:
Update to 3.0.3:
- CVE-2025-11232: invalid characters cause assert (bsc#1252863).
- CVE-2026-3608: stack overflow via maliciously crafted message (bsc#1260380).
Changelog:
- A large number of bracket pairs in a JSON payload directed to
any endpoint would result in a stack overflow, due to recursive
calls when parsing the JSON. This has been fixed.
(CVE-2026-3608)
[bsc#1260380]
- When a hostname or FQDN received from a client is reduced to an
empty string by hostname sanitizing, kea-dhcp4 and kea-dhcp6
will now drop the option.
(CVE-2025-11232)
[bsc#1252863]
- A null dereference is now no longer possible when configuring
the Control Agent with a socket that lacks the mandatory
socket-name entry.
- UNIX sockets are now created as group-writable.
- Removed logging an error in ping check hook library if using
lease cache treshold.
- Fixed deadlock in ping-check hooks library.
- Fixed a data race in ping-check hooks library.
Affected software
openSUSE-SU-2026:20452-1 is recorded against 1 package.
- kea (fixed in 3.0.3-160000.1.1)
Timeline and source
Published on 1 April 2026 and last revised on 3 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| kea | — | 3.0.3-160000.1.1 |
References
Similar Threats
- Unknown RHSA-2026:11344
- Unknown RLSA-2026:7342
- Unknown RHSA-2026:7342
- Unknown SUSE-SU-2026:1091-1
- Unknown ALPINE-CVE-2026-3608
Free Vulnerability Check
Is your site affected by openSUSE-SU-2026:20452-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2026:20452-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.