gpp_maybe Security update for kea
SUSE-SLE-Module-Basesystem-15-SP7-2026-1378


This update for kea fixes the following issues: Update to release 2.6.5: * A large number of bracket pairs in a JSON payload directed to any endpoint would result in a stack overflow, due to recursive calls when parsing the JSON. This has been fixed. (CVE-2026-3608) [bsc#1260380] * A null dereference is now no longer possible when configuring the Control Agent with a socket that lacks the mandatory socket-name entry. * UNIX sockets are now created as group-writable. * Corrected an issue in logging configuration when parsing "syslog:" * Earlier Kea versions could crash when handling misconfigured global reservations. This has been fixed. * Support for recent versions of Sphinx has been added.

  • Release Date
    Apr 16 2026
  • References
    Bugzilla: 1260380
    CVEs: CVE-2026-3608
  • Type
    security
  • Severity
    important

cloud_download Downloads

Basesystem Module 15.7 ppc64le
  • Packages
    kea
    Dynamic Host Configuration Protocol daemon
    2.6.5-150700.3.6.1 lock src
    python3-kea
    Python interface to Kea DHCP server
    2.6.5-150700.3.6.1 lock rpm
Basesystem Module 15.7 s390x
  • Packages
    kea
    Dynamic Host Configuration Protocol daemon
    2.6.5-150700.3.6.1 lock src
    python3-kea
    Python interface to Kea DHCP server
    2.6.5-150700.3.6.1 lock rpm
Basesystem Module 15.7 x86_64
  • Packages
    kea
    Dynamic Host Configuration Protocol daemon
    2.6.5-150700.3.6.1 lock src
    python3-kea
    Python interface to Kea DHCP server
    2.6.5-150700.3.6.1 lock rpm
Basesystem Module 15.7 aarch64
  • Packages
    kea
    Dynamic Host Configuration Protocol daemon
    2.6.5-150700.3.6.1 lock src
    python3-kea
    Python interface to Kea DHCP server
    2.6.5-150700.3.6.1 lock rpm