{"id":"SUSE-SU-2026:1378-1","summary":"Security update for kea","details":"This update for kea fixes the following issues:\n\nUpdate to release 2.6.5:\n\n  * A large number of bracket pairs in a JSON payload directed to\n    any endpoint would result in a stack overflow, due to recursive\n    calls when parsing the JSON. This has been fixed.\n    (CVE-2026-3608)\n    [bsc#1260380]\n  * A null dereference is now no longer possible when configuring\n    the Control Agent with a socket that lacks the mandatory\n    socket-name entry.\n  * UNIX sockets are now created as group-writable.\n  * Corrected an issue in logging configuration when parsing\n    'syslog:'\n  * Earlier Kea versions could crash when handling misconfigured\n    global reservations. This has been fixed.\n  * Support for recent versions of Sphinx has been added.\n","modified":"2026-04-17T09:00:57.838009Z","published":"2026-04-16T07:19:46Z","related":["CVE-2026-3608"],"upstream":["CVE-2026-3608"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261378-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260380"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3608"}],"affected":[{"package":{"name":"kea","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/kea&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.5-150700.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"python3-kea":"2.6.5-150700.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1378-1.json"}},{"package":{"name":"kea","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP7","purl":"pkg:rpm/suse/kea&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.5-150700.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"kea-hooks":"2.6.5-150700.3.6.1","libkea-cc69":"2.6.5-150700.3.6.1","libkea-cfgclient67":"2.6.5-150700.3.6.1","libkea-database62":"2.6.5-150700.3.6.1","libkea-dhcp++92":"2.6.5-150700.3.6.1","libkea-exceptions33":"2.6.5-150700.3.6.1","libkea-hooks102":"2.6.5-150700.3.6.1","libkea-asiolink72":"2.6.5-150700.3.6.1","libkea-d2srv47":"2.6.5-150700.3.6.1","libkea-eval69":"2.6.5-150700.3.6.1","libkea-log61":"2.6.5-150700.3.6.1","libkea-mysql71":"2.6.5-150700.3.6.1","libkea-pgsql71":"2.6.5-150700.3.6.1","libkea-process76":"2.6.5-150700.3.6.1","libkea-util-io0":"2.6.5-150700.3.6.1","kea-devel":"2.6.5-150700.3.6.1","kea":"2.6.5-150700.3.6.1","libkea-cryptolink50":"2.6.5-150700.3.6.1","libkea-util87":"2.6.5-150700.3.6.1","kea-doc":"2.6.5-150700.3.6.1","libkea-asiodns49":"2.6.5-150700.3.6.1","libkea-dhcpsrv112":"2.6.5-150700.3.6.1","libkea-dns++57":"2.6.5-150700.3.6.1","libkea-http72":"2.6.5-150700.3.6.1","libkea-stats41":"2.6.5-150700.3.6.1","libkea-tcp19":"2.6.5-150700.3.6.1","libkea-dhcp_ddns57":"2.6.5-150700.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1378-1.json"}}],"schema_version":"1.7.5"}