CVE-2019-6472: ISC Kea
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.
Affected products
- ISC Kea: from 1.4.0, up to and including 1.5.0; version 1.6.0 only
Published 2019-10-16. Last modified 2026-06-17.