Skip to content
Critical Denial of Service Vulnerability in Kea DHCP Affects Ubuntu Systems

Critical Denial of Service Vulnerability in Kea DHCP Affects Ubuntu Systems

First seen 8 Jun 2026, 22:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 9, 2026 at 22:30 UTC

A vulnerability in Kea DHCP, discovered by Ali Norouzi, allows remote attackers to crash the service by sending specially crafted messages over API sockets and HA listeners. This flaw affects Ubuntu versions 25.10 and 24.04 LTS, leading to a denial of service. The issue can be mitigated by updating to specific package versions. Users are advised to restart their Kea DHCP server instances after applying the updates. The vulnerability is documented under Ubuntu Security Notice USN-8403-1. No CVE has been assigned yet, but the issue poses a significant risk to systems running affected versions. The problem was disclosed on June 8, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 104d ago How this analysis works

Timeline

2026-06-08
Kea DHCP vulnerability disclosed
Ali Norouzi reported a flaw in Kea DHCP that allows remote denial of service attacks via crafted messages.
Ubuntu
2026-06-08
Ubuntu Security Notice USN-8403-1 issued
Ubuntu released an advisory detailing the Kea DHCP vulnerability and recommended updates for affected versions.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed