Linuxsecurity Fedora 42 and 43 Kea 3.0.3 Denial of Service Vulnerability Fix Released
Article Content
- •CVE-2026-3608 is a Denial of Service vulnerability in Kea DHCP servers.
- •Affected systems include Fedora 42 and Fedora 43 with Kea DHCP server installed.
- •Users should upgrade to version 3.0.3 to mitigate the vulnerability immediately.
On April 8, 2026, two articles reported on the release of version 3.0.3 of the Kea DHCP server, which addresses a critical Denial of Service vulnerability identified as CVE-2026-3608. This vulnerability, published on March 25, 2026, allows attackers to exploit the DHCP server through maliciously crafted messages, potentially disrupting services for affected users. The vulnerability impacts both Fedora 42 and Fedora 43 systems running the Kea DHCP server. Users are advised to upgrade to the patched version 3.0.3 to mitigate the risk. The update can be installed using the 'dnf' package manager with specific commands provided in the articles. The vulnerability's scope includes all systems utilizing the affected DHCP implementation. The articles emphasize the importance of applying the update promptly to avoid service disruptions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Fedora and CVE-2026-3608 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…