CVE-2025-11232

7.5

ISC · Kea

A configuration-dependent flaw in ISC Kea DHCP4 allows unauthenticated remote attackers to cause a service crash by sending crafted option content.

Executive summary

ISC Kea versions 3.0.1 and 3.1.1 through 3.1.2 are vulnerable to a denial of service attack due to improper handling of specific configuration parameters.

Vulnerability

The software fails to correctly process specific client-provided option content when three specific configuration parameters are set to their default states. This allows an unauthenticated remote attacker to trigger a crash of the kea-dhcp4 process, resulting in a denial of service.

Business impact

Successful exploitation of this vulnerability results in the unexpected termination of the DHCP service, which directly impacts network connectivity for all clients relying on the affected infrastructure. With a CVSS score of 7.5, the risk is rated as High because the attack is automatable and requires no authentication, potentially leading to widespread service disruption within internal or external networks.

Remediation

Immediate Action: Upgrade to Kea version 3.0.2 or 3.1.3 immediately to address the underlying memory management flaw.

Proactive Monitoring: Monitor service logs for unexpected process exits or frequent restarts of the kea-dhcp4 service.

Compensating Controls: Ensure that the DHCP server is isolated from untrusted networks via firewalls or ACLs to limit the reach of malicious packets.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the high severity and the potential for a complete service outage, administrators should prioritize updating to the patched versions as soon as possible. Because the vulnerability is triggered by specific, common default configurations, the risk of accidental or malicious disruption is significant, necessitating prompt remediation.

More ISC CVEs

Sources

Originally found and disclosed by ISC would like to thank Siniša Uskoković and Ralf Steuer from Vienna University of Economics and Business for bringing t, per the CVE Program record.