Kea crash upon interaction between specific client options and subnet selection
Vulnerability Description
If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process will abort with an assertion failure. This happens only if the client request is unicast directly to Kea; broadcast messages do not cause the problem. This issue affects Kea versions 2.7.1 through 2.7.9, 3.0.0, and 3.1.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-40779
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- ISC would like to thank the following for bringing this vulnerability to our attention: * Jochen M. * Martin Dinev, Trading212 * Ashwani Kumar, Post Graduate Institute of Medical Education & Research, Chandigarh, India * Bret Giddings, University of Essex * Florian Ritterhoff, Munich University of Applied Sciences