CVE-2026-3608: ISC Kea

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving daemon to exit with a stack overflow error. This issue affects Kea versions 2.6.0 through 2.6.4 and 3.0.0 through 3.0.2.

Affected products

  • ISC Kea: from 2.6.0, up to and including 2.6.4; from 3.0.0, up to and including 3.0.2
  • Red Hat Red Hat Enterprise Linux 10: before 0:3.0.1-3.el10_1 (fixed in 0:3.0.1-3.el10_1)
  • Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:2.6.3-2.el10_0.3 (fixed in 0:2.6.3-2.el10_0.3)

Published 2026-03-25. Last modified 2026-07-15.