Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 660988 (CVE-2018-5739) - <net-misc/kea-1.4_p1: Memory Leak Denial of Service Vulnerability
Summary: <net-misc/kea-1.4_p1: Memory Leak Denial of Service Vulnerability
Alias: CVE-2018-5739
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
Whiteboard: ~3 [noglsa cve]
Depends on:
Reported: 2018-07-12 09:22 UTC by Florian Schuhmacher
Modified: 2019-03-24 05:29 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Florian Schuhmacher 2018-07-12 09:22:31 UTC
Kea DHCP 1.4.0 may fail to release memory after temporarily storing
client network packets.  This causes a constant increase in memory
consumption that can cause server resources to become exhausted,
leading to loss of DHCP server functionality.

Gentoo Security Scout
Florian Schuhmacher
Comment 1 Larry the Git Cow gentoo-dev 2018-07-12 09:26:03 UTC
The bug has been referenced in the following commit(s):

commit 1eb7529cbbd47cd674f5bce9c951a356c36cde07
Author:     Lars Wendler <>
AuthorDate: 2018-07-12 09:25:38 +0000
Commit:     Lars Wendler <>
CommitDate: 2018-07-12 09:25:57 +0000

    net-misc/kea: Security cleanup.
    Package-Manager: Portage-2.3.42, Repoman-2.3.9

 net-misc/kea/Manifest         |  1 -
 net-misc/kea/kea-1.4.0.ebuild | 68 -------------------------------------------
 2 files changed, 69 deletions(-)
Comment 2 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2018-07-12 09:27:39 UTC
I already added version 1.4.0_p1 to the tree today. Now I've also removed 1.4.0 version. 
Any information about older versions being affected?

No need to initialize stabilization process as there's no stable version of kea in the tree yet.
Comment 3 Florian Schuhmacher 2018-07-12 17:28:39 UTC
The memory leak is connected to the callout handle store, which was
added in Kea 1.4.0 to support additional hooks capabilities.

Prior to 1.4.0 it did not exist, so Kea 1.4.0 (along with its
interim development releases, e.g. 1.4.0b1) would be the only release(s)
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2019-03-24 05:29:07 UTC
For posterity: