Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 956994 (CVE-2025-32801, CVE-2025-32802, CVE-2025-32803) - net-misc/kea: Multiple vulnerabilities
Summary: net-misc/kea: Multiple vulnerabilities
Status: IN_PROGRESS
Alias: CVE-2025-32801, CVE-2025-32802, CVE-2025-32803
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
URL: https://www.openwall.com/lists/oss-se...
Whiteboard: ~2 [ebuild]
Keywords:
Depends on: 928320
Blocks:
  Show dependency tree
 
Reported: 2025-06-01 05:10 UTC by Sam James
Modified: 2025-06-04 06:38 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2025-06-01 05:10:50 UTC
"""
Subject: ISC has disclosed three vulnerabilities in Kea (CVE-2025-32801,
 CVE-2025-32802, CVE-2025-32803)

On 28 May 2025 we (Internet Systems Consortium) disclosed three 
vulnerabilities affecting our Kea software:

- CVE-2025-32801:       Loading a malicious hook library can lead to 
local privilege escalation https://kb.isc.org/docs/cve-2025-32801
- CVE-2025-32802:       Insecure handling of file paths allows multiple 
local attacks https://kb.isc.org/docs/cve-2025-32802
- CVE-2025-32803:       Insecure file permissions can result in 
confidential information leakage https://kb.isc.org/docs/cve-2025-32803

New versions of Kea are available from https://www.isc.org/downloads

- https://downloads.isc.org/isc/kea/2.4.2/
- https://downloads.isc.org/isc/kea/2.6.3/
- https://downloads.isc.org/isc/kea/2.7.9/

With the public announcement of these vulnerabilities, the embargo 
period is ended and any updated software packages that have been 
prepared may be released.
"""
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2025-06-04 02:00:05 UTC
I've filed bug 957113 for the non-security issues mentioned at https://security.opensuse.org/2025/05/28/kea-dhcp-security-issues.html#65-gentoo-linux.