SUSE-SU-2026:20989-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202620989-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20989-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:20989-1
Upstream
CVE (2)
  • CVE-2025-11232
  • CVE-2026-3608
Related
Published
2026-04-01T09:22:53Z
Modified
2026-04-10T18:24:39Z
Summary
Security update for kea
Details

This update for kea fixes the following issues:

Update to 3.0.3:

  • CVE-2025-11232: invalid characters cause assert (bsc#1252863).
  • CVE-2026-3608: stack overflow via maliciously crafted message (bsc#1260380).

Changelog:

  • A large number of bracket pairs in a JSON payload directed to any endpoint would result in a stack overflow, due to recursive calls when parsing the JSON. This has been fixed. (CVE-2026-3608) [bsc#1260380]
  • When a hostname or FQDN received from a client is reduced to an empty string by hostname sanitizing, kea-dhcp4 and kea-dhcp6 will now drop the option. (CVE-2025-11232) [bsc#1252863]
  • A null dereference is now no longer possible when configuring the Control Agent with a socket that lacks the mandatory socket-name entry.
  • UNIX sockets are now created as group-writable.
  • Removed logging an error in ping check hook library if using lease cache treshold.
  • Fixed deadlock in ping-check hooks library.
  • Fixed a data race in ping-check hooks library.
References

Affected packages

SUSE:Linux Enterprise Server 16.0 / kea

Package

Name
kea
Purl
pkg:rpm/suse/kea&distro=SUSE%20Linux%20Enterprise%20Server%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.3-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "kea":  "3.0.3-160000.1.1",
            "kea-devel":  "3.0.3-160000.1.1",
            "kea-doc":  "3.0.3-160000.1.1",
            "kea-hooks":  "3.0.3-160000.1.1",
            "libkea-asiodns62":  "3.0.3-160000.1.1",
            "libkea-asiolink88":  "3.0.3-160000.1.1",
            "libkea-cc83":  "3.0.3-160000.1.1",
            "libkea-cfgrpt3":  "3.0.3-160000.1.1",
            "libkea-config84":  "3.0.3-160000.1.1",
            "libkea-cryptolink64":  "3.0.3-160000.1.1",
            "libkea-d2srv63":  "3.0.3-160000.1.1",
            "libkea-database76":  "3.0.3-160000.1.1",
            "libkea-dhcp109":  "3.0.3-160000.1.1",
            "libkea-dhcp_ddns68":  "3.0.3-160000.1.1",
            "libkea-dhcpsrv131":  "3.0.3-160000.1.1",
            "libkea-dns71":  "3.0.3-160000.1.1",
            "libkea-eval84":  "3.0.3-160000.1.1",
            "libkea-exceptions45":  "3.0.3-160000.1.1",
            "libkea-hooks121":  "3.0.3-160000.1.1",
            "libkea-http87":  "3.0.3-160000.1.1",
            "libkea-log-interprocess3":  "3.0.3-160000.1.1",
            "libkea-log75":  "3.0.3-160000.1.1",
            "libkea-mysql88":  "3.0.3-160000.1.1",
            "libkea-pgsql88":  "3.0.3-160000.1.1",
            "libkea-process91":  "3.0.3-160000.1.1",
            "libkea-stats53":  "3.0.3-160000.1.1",
            "libkea-tcp33":  "3.0.3-160000.1.1",
            "libkea-util-io12":  "3.0.3-160000.1.1",
            "libkea-util102":  "3.0.3-160000.1.1",
            "python3-kea":  "3.0.3-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20989-1.json"

SUSE:Linux Enterprise Server for SAP applications 16.0 / kea

Package

Name
kea
Purl
pkg:rpm/suse/kea&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.3-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "kea":  "3.0.3-160000.1.1",
            "kea-devel":  "3.0.3-160000.1.1",
            "kea-doc":  "3.0.3-160000.1.1",
            "kea-hooks":  "3.0.3-160000.1.1",
            "libkea-asiodns62":  "3.0.3-160000.1.1",
            "libkea-asiolink88":  "3.0.3-160000.1.1",
            "libkea-cc83":  "3.0.3-160000.1.1",
            "libkea-cfgrpt3":  "3.0.3-160000.1.1",
            "libkea-config84":  "3.0.3-160000.1.1",
            "libkea-cryptolink64":  "3.0.3-160000.1.1",
            "libkea-d2srv63":  "3.0.3-160000.1.1",
            "libkea-database76":  "3.0.3-160000.1.1",
            "libkea-dhcp109":  "3.0.3-160000.1.1",
            "libkea-dhcp_ddns68":  "3.0.3-160000.1.1",
            "libkea-dhcpsrv131":  "3.0.3-160000.1.1",
            "libkea-dns71":  "3.0.3-160000.1.1",
            "libkea-eval84":  "3.0.3-160000.1.1",
            "libkea-exceptions45":  "3.0.3-160000.1.1",
            "libkea-hooks121":  "3.0.3-160000.1.1",
            "libkea-http87":  "3.0.3-160000.1.1",
            "libkea-log-interprocess3":  "3.0.3-160000.1.1",
            "libkea-log75":  "3.0.3-160000.1.1",
            "libkea-mysql88":  "3.0.3-160000.1.1",
            "libkea-pgsql88":  "3.0.3-160000.1.1",
            "libkea-process91":  "3.0.3-160000.1.1",
            "libkea-stats53":  "3.0.3-160000.1.1",
            "libkea-tcp33":  "3.0.3-160000.1.1",
            "libkea-util-io12":  "3.0.3-160000.1.1",
            "libkea-util102":  "3.0.3-160000.1.1",
            "python3-kea":  "3.0.3-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20989-1.json"