Linuxsecurity
Critical Denial of Service Vulnerability in Kea DHCP Affects Ubuntu Systems
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A vulnerability in Kea DHCP, discovered by Ali Norouzi, allows remote attackers to crash the service by sending specially crafted messages over API sockets and HA listeners. This flaw affects Ubuntu versions 25.10 and 24.04 LTS, leading to a denial of service. The issue can be mitigated by updating to specific package versions. Users are advised to restart their Kea DHCP server instances after applying the updates. The vulnerability is documented under Ubuntu Security Notice USN-8403-1. No CVE has been assigned yet, but the issue poses a significant risk to systems running affected versions. The problem was disclosed on June 8, 2026.
Key Points: • Kea DHCP vulnerability allows remote denial of service attacks on affected Ubuntu systems. • The flaw affects Ubuntu versions 25.10 and 24.04 LTS, requiring urgent updates. • Users must restart Kea DHCP server instances post-update to ensure security.