{"id":"SUSE-SU-2026:1548-1","summary":"Security update for kea","details":"This update for kea fixes the following issues:\n\nUpdate to release 2.6.5.\n\nSecurity issues fixed:\n\n- CVE-2026-3608: stack overflow error via specially crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or\n  kea-dhcp6 daemons(bsc#1260380).  \n\nOther updates and bugfixes:\n\n- A null dereference is now no longer possible when configuring the Control Agent with a socket that lacks the\n  mandatory socket-name entry.\n- UNIX sockets are now created as group-writable.\n- Corrected an issue in logging configuration when parsing 'syslog:'.\n- Fixed crash when handling misconfigured global reservations.\n- Support for recent versions of Sphinx has been added.\n","modified":"2026-04-23T08:45:24.048079Z","published":"2026-04-22T09:40:51Z","related":["CVE-2026-3608"],"upstream":["CVE-2026-3608"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261548-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260380"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3608"}],"affected":[{"package":{"name":"kea","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/kea&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.5-150600.13.9.1"}]}],"ecosystem_specific":{"binaries":[{"libkea-hooks102":"2.6.5-150600.13.9.1","libkea-http72":"2.6.5-150600.13.9.1","libkea-mysql71":"2.6.5-150600.13.9.1","libkea-util-io0":"2.6.5-150600.13.9.1","kea-hooks":"2.6.5-150600.13.9.1","libkea-asiolink72":"2.6.5-150600.13.9.1","libkea-process76":"2.6.5-150600.13.9.1","libkea-tcp19":"2.6.5-150600.13.9.1","libkea-util87":"2.6.5-150600.13.9.1","python3-kea":"2.6.5-150600.13.9.1","kea-devel":"2.6.5-150600.13.9.1","libkea-cc69":"2.6.5-150600.13.9.1","libkea-cryptolink50":"2.6.5-150600.13.9.1","libkea-dhcp_ddns57":"2.6.5-150600.13.9.1","libkea-dhcpsrv112":"2.6.5-150600.13.9.1","libkea-dns++57":"2.6.5-150600.13.9.1","libkea-log61":"2.6.5-150600.13.9.1","libkea-pgsql71":"2.6.5-150600.13.9.1","kea-doc":"2.6.5-150600.13.9.1","libkea-asiodns49":"2.6.5-150600.13.9.1","libkea-cfgclient67":"2.6.5-150600.13.9.1","libkea-d2srv47":"2.6.5-150600.13.9.1","libkea-dhcp++92":"2.6.5-150600.13.9.1","libkea-eval69":"2.6.5-150600.13.9.1","libkea-exceptions33":"2.6.5-150600.13.9.1","libkea-stats41":"2.6.5-150600.13.9.1","kea":"2.6.5-150600.13.9.1","libkea-database62":"2.6.5-150600.13.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1548-1.json"}},{"package":{"name":"kea","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/kea&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.5-150600.13.9.1"}]}],"ecosystem_specific":{"binaries":[{"libkea-mysql71":"2.6.5-150600.13.9.1","libkea-pgsql71":"2.6.5-150600.13.9.1","libkea-process76":"2.6.5-150600.13.9.1","libkea-tcp19":"2.6.5-150600.13.9.1","python3-kea":"2.6.5-150600.13.9.1","libkea-asiodns49":"2.6.5-150600.13.9.1","libkea-cc69":"2.6.5-150600.13.9.1","libkea-d2srv47":"2.6.5-150600.13.9.1","libkea-dhcp++92":"2.6.5-150600.13.9.1","libkea-dhcpsrv112":"2.6.5-150600.13.9.1","libkea-util-io0":"2.6.5-150600.13.9.1","kea-doc":"2.6.5-150600.13.9.1","kea-hooks":"2.6.5-150600.13.9.1","kea":"2.6.5-150600.13.9.1","libkea-cfgclient67":"2.6.5-150600.13.9.1","libkea-exceptions33":"2.6.5-150600.13.9.1","libkea-util87":"2.6.5-150600.13.9.1","kea-devel":"2.6.5-150600.13.9.1","libkea-asiolink72":"2.6.5-150600.13.9.1","libkea-dhcp_ddns57":"2.6.5-150600.13.9.1","libkea-dns++57":"2.6.5-150600.13.9.1","libkea-eval69":"2.6.5-150600.13.9.1","libkea-hooks102":"2.6.5-150600.13.9.1","libkea-log61":"2.6.5-150600.13.9.1","libkea-stats41":"2.6.5-150600.13.9.1","libkea-cryptolink50":"2.6.5-150600.13.9.1","libkea-database62":"2.6.5-150600.13.9.1","libkea-http72":"2.6.5-150600.13.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1548-1.json"}}],"schema_version":"1.7.5"}