Critical Denial of Service Vulnerability in Kea DHCP Affects Ubuntu Systems

Critical Denial of Service Vulnerability in Kea DHCP Affects Ubuntu Systems

First seen 8 Jun 2026, 22:52 UTC UbuntuLinuxsecurity 90% similarity 60.6

Article Content

Browse articles
ThreatCluster

A vulnerability in Kea DHCP, discovered by Ali Norouzi, allows remote attackers to crash the service by sending specially crafted messages over API sockets and HA listeners. This flaw affects Ubuntu versions 25.10 and 24.04 LTS, leading to a denial of service. The issue can be mitigated by updating to specific package versions. Users are advised to restart their Kea DHCP server instances after applying the updates. The vulnerability is documented under Ubuntu Security Notice USN-8403-1. No CVE has been assigned yet, but the issue poses a significant risk to systems running affected versions. The problem was disclosed on June 8, 2026.

Key Points: • Kea DHCP vulnerability allows remote denial of service attacks on affected Ubuntu systems. • The flaw affects Ubuntu versions 25.10 and 24.04 LTS, requiring urgent updates. • Users must restart Kea DHCP server instances post-update to ensure security.

ThreatCluster AI

Timeline

2026-06-08
Kea DHCP vulnerability disclosed
Ali Norouzi reported a flaw in Kea DHCP that allows remote denial of service attacks via crafted messages.
Ubuntu
2026-06-08
Ubuntu Security Notice USN-8403-1 issued
Ubuntu released an advisory detailing the Kea DHCP vulnerability and recommended updates for affected versions.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story