CVE-2015-8373: ISC Kea

Medium severity, CVSS 6.8. EPSS: 3.7% chance of exploitation in the next 30 days.

The kea-dhcp4 and kea-dhcp6 servers 0.9.2 and 1.0.0-beta in ISC Kea, when certain debugging settings are used, allow remote attackers to cause a denial of service (daemon crash) via a malformed packet.

Affected products

  • ISC Kea: version 0.9.2 only; version 1.0.0 only

Published 2015-12-22. Last modified 2026-06-17.