#1112247 isc-kea: CVE-2025-40779

Package:
src:isc-kea
Source:
src:isc-kea
Submitter:
Salvatore Bonaccorso
Date:
2025-08-28 19:53:03 UTC
Severity:
normal
Tags:
#1112247#5
Date:
2025-08-27 20:22:22 UTC
From:
To:
Hi,

The following vulnerability was published for isc-kea.

CVE-2025-40779[0]:
| Kea crash upon interaction between specific client options and
| subnet selection


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-40779
https://www.cve.org/CVERecord?id=CVE-2025-40779
[1] https://kb.isc.org/docs/cve-2025-40779
[2] https://gitlab.isc.org/isc-projects/kea/-/commit/b25d7e8a81273e4099bf6c7f639ed774de2f3d08

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1112247#10
Date:
2025-08-28 19:25:41 UTC
From:
To:
Hi Salvatore,

From the CVE itself, looks like version 2.6.3-2 is not affected by the
vulnerability. There is an older version in oldstable, which again
according to the CVE is "likely unaffected".

Do you think we should mark the oldstable version affected by this bug?

Thanks,

Paride

#1112247#15
Date:
2025-08-28 19:43:36 UTC
From:
To:
Hi Paride,

I might have confused something with the report, let me double-check I
think I missed where the issue got introduced. Will update the bug
shortly if it turns to be right and close it.

FWIW, as general note (not specific to this bug), ISC does not assess
not supported versions, so any statement about earlier versions need
to be taken with care and have actual inspection in any case.

Regards,
Salvatore

#1112247#20
Date:
2025-08-28 19:52:08 UTC
From:
To:
Hi Paride,

You are right, I have updated the security-tracker as with
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf971cd772706798f7fb8875d8b4299bfbc43710

Regards,
Salvatore

#1112247#27
Date:
2025-08-28 19:52:08 UTC
From:
To:
Hi Paride,

You are right, I have updated the security-tracker as with
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf971cd772706798f7fb8875d8b4299bfbc43710

Regards,
Salvatore