CVE-2026-3608Patch

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving daemon to exit with a stack overflow error. This issue affects Kea versions 2.6.0 through 2.6.4 and 3.0.0 through 3.0.2.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-617

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 13 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 10 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 3 mentions (2026-03-27); latest day: 1
  • 13 total mentions across 8 days

Deep dive

Activity timeline13 mentions / 8d
01223Mentions · 2026-03-25: 2Mentions · 2026-03-26: 1Mentions · 2026-03-27: 3Mentions · 2026-03-28: 3Mentions · 2026-04-02: 1Mentions · 2026-04-04: 1Mentions · 2026-04-08: 1Mentions · 2026-04-22: 1PoC Mentioned / Linked · 2026-03-27: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-27: 2Patch / Workaround · 2026-03-28: 2Patch / Workaround · 2026-04-08: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 3Technical Details · 2026-04-02: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-22: 103-2503-2603-2703-2804-0204-0404-0804-22
Signal classification3 categories
Patch
753.8%
Disclosure
430.8%
General
215.4%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-252
General1Patch1
2026-03-261
Patch1
2026-03-273
Disclosure1Patch2
2026-03-283
Disclosure1Patch2
2026-04-021
Disclosure1
2026-04-041
General1
2026-04-081
Patch1
2026-04-221
Disclosure1
Full discourse13 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-3608: Kea: Stack overflow in Kea daemons https://www.openwall.com/lists/oss-security/2026/03/25/6 Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving daemon to exit

    Post summary

    A new stack overflow vulnerability (CVE-2026-3608) was disclosed in Kea DHCP daemons, causing a crash when a malicious message is sent to the API or HA listener.

    00061518
    4.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    ISC warns of a high-severity stack overflow in Kea DHCP (CVE-2026-3608). Remote attackers can crash daemons and kill network services. Upgrade to 3.0.3 now. #KeaDHCP #ISC #CyberSecurity #InfoSec #NetworkAdmin #Vulnerability #PatchAlert #DHCP #IPAM https://securityonline.info/kea-dhcp-stack-overflow-vulnerability-cve-2026-3608/ https://t.co/MPP0vrdN4W

    Post summary

    ISC alerts about a high‑severity stack overflow in Kea DHCP (CVE‑2026‑3608) that can crash services, urging users to upgrade to version 3.0.3 to apply the patch.

    01010367
    10.9K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    CVE-2026-3608: A stack overflow in Kea DHCP (kea-ctrl-agent, dhcp4, dhcp6) lets any attacker crash your service remotely. Read more: https://tinyurl.com/bd8tmync #openSUSE https://t.co/Cu25WolZWG

    Post summary

    A stack overflow vulnerability in Kea DHCP’s kea‑ctrl‑agent, dhcp4, and dhcp6 modules allows attackers to crash the service remotely. Further details are referenced via an external URL.

    1000090
    1.5K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Kea DHCP の脆弱性 CVE-2026-3608 が FIX:完全なサービス拒否 (DoS) に至る恐れ https://iototsecnews.jp/2026/03/27/isc-issues-critical-warning-over-kea-dhcp-vulnerability-that-could-remotely-crash-services/ Kea DHCP サーバの深刻な脆弱性 CVE-2026-3608 (CVSS:7.5) について解説する記事です。この問題の原因は、Kea の主要なデーモン群が使用するメモリ領域で発生するスタック・オーバーフローにあります。コントロール・エージェントや IPv4/IPv6 サービスなどのコンポーネントが、細工された不正なパケットを API ソケットなどをを通じて受信した際に、そのペイロードを安全に処理できず、プロセスが即座にクラッシュしてしまいます。この脆弱性を悪用されると、深刻なサービス拒否 (DoS) 状態に陥る恐れがあります。ご利用のチームは、ご注意ください。 #CVE20263608 #KeaDHCP #Vulnerability

    Post summary

    The post announces Kea DHCP CVE‑2026‑3608, a stack‑overflow vulnerability that can cause a complete service denial, and urges vigilance.

    01000124
    481 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora 42 and 43 ship Kea DHCP 3.0.3 to fix critical CVE-2026-3608 Denial of Service flaw, admins urged to upgrade immediately. https://threatcluster.io/cluster/fedora-42-and-43-kea-303-denial-of-service-vulnerability-fix-a3a31359

    Post summary

    Fedora 42 and 43 now ship Kea DHCP 3.0.3 to patch the critical CVE-2026-3608 Denial‑of‑Service vulnerability; administrators are urged to upgrade immediately.

    0000047
    133 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3608 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3608 #CVE-2026-3608 #CVE #High  #CyberSecurity #InfoSec https://t.co/Hygmsa64gp

    Post summary

    A brief tweet announcing CVE-2026-3608 with a severity score of 7.5, but lacking details on exploitation, vulnerability characteristics, or mitigation.

    0000032
    123 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical vulnerability CVE-2026-3608 in Kea DHCP servers can cause remote service crashes. Immediate patching or TLS configuration is essential. Link: https://thedailytechfeed.com/critical-vulnerability-in-kea-dhcp-exposes-networks-to-remote-attacks-update-urgently-recommended/ #Vulnerability #CVE #Kea #DHCP #Servers #Remote #Service #Crashes #Patching #TLS #Configuration #Security #Network #Update #Urgent #Attack #Technology #Protection #Cyber #System #Tech

    Post summary

    The post highlights a newly disclosed CVE‑2026‑3608 in Kea DHCP servers, urging immediate patching or TLS configuration, but does not provide PoC or exploit details.

    000004
    269 followersView on X
  • StrongKeep Cybersecurity@StrongKeepCyber
    Patch

    ICYMI: A high-severity flaw in Kea DHCP (CVE-2026-3608) could crash services remotely. SMEs should patch quickly, verify access controls, and monitor DHCP traffic for anomalies. Stay calm, patch promptly, and test in a maintenance window. Read more: https://cybersecuritynews.com/isc-warns-kea-dhcp-flaw/

    Post summary

    The message highlights a high‑severity flaw in Kea DHCP (CVE‑2026‑3608) that could cause remote service crashes and urges immediate patching and monitoring.

    0000047
    2 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    JUST IN: Critical Kea DHCP bug CVE-2026-3608 lets remote unauthenticated attackers crash ISC servers, threatening IP allocation for millions of users. https://threatcluster.io/cluster/critical-vulnerability-in-kea-dhcp-server-allows-remote-cras-e3f33610

    Post summary

    A new critical vulnerability (CVE‑2026‑3608) in ISC Kea DHCP servers has been disclosed. It permits remote unauthenticated attackers to crash servers, potentially disrupting IP allocation for millions of users.

    0000050
    128 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 Critical Kea DHCP Flaw #CVE-2026-3608: Unauthenticated Remote DoS Threatens Enterprise Networks—Patch Now + Video https://undercodetesting.com/critical-kea-dhcp-flaw-cve-2026-3608-unauthenticated-remote-dos-threatens-enterprise-networks-patch-now-video/ Educational Purposes!

    Post summary

    The article announces a critical un‑authenticated remote DoS flaw in Kea DHCP (CVE‑2026‑3608), provides a video demonstration, and urges immediate patching.

    0000036
    453 followersView on X
  • StrongKeep Cybersecurity@StrongKeepCyber
    Patch

    Kea DHCP stack overflow bug (CVE-2026-3608) could disrupt DHCP services. For small businesses, patch your Kea deployments, test updates in a staging network, and monitor for any service hiccups. Stay calm, patch smart, and keep clients happy. Source: https://securityonline.info/kea-dhcp-stack-overflow-vulnerability-cve-2026-3608/

    Post summary

    An advisory warns that a stack overflow bug in Kea DHCP (CVE‑2026‑3608) can disrupt services, and recommends patching deployments immediately.

    0000032
    2 followersView on X
  • Fernando Karl@fernandokarl
    Patch

    ⚠️ #CVE-2026-3608 alert! Stack overflow vulnerability in Kea's DHCP services could cause critical DoS. 📉 Update to Kea 2.6.5 or 3.0.3 ASAP and secure API access! Act now to protect your network! 🔒 👉 Read more: https://www.tenable.com/cve/CVE-2026-3608 #CyberSecurity #ThreatIntelligence

    Post summary

    The post alerts about a stack‑overflow CVE in Kea DHCP that leads to DoS and urges users to upgrade to 2.6.5 or 3.0.3 and secure API access, with a link to Tenable for details.

    0000049
    257 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-3608 Stack Overflow Vulnerability in ISC Kea DHCP Daemons via Malicious Message https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3608

    Post summary

    Only a CVE identifier and a link to a vulnerability details page are provided, with no substantive technical or exploit information.

    0000036
    4.0K followersView on X

Explore more