CVE-2025-40779: ISC Kea
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process will abort with an assertion failure. This happens only if the client request is unicast directly to Kea; broadcast messages do not cause the problem. This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.
Affected products
- ISC Kea: from 2.7.1, up to and including 2.7.9; version 3.0.0 only; version 3.1.0 only
Published 2025-08-27. Last modified 2026-06-17.