ThreatCluster[verified]@threatclusterPatch
Fedora 42 and 43 now ship Kea DHCP 3.0.3 to patch the critical CVE-2026-3608 Denial‑of‑Service vulnerability; administrators are urged to upgrade immediately.
The Daily Tech Feed[verified]@dailytechonxPatch
The post highlights a newly disclosed CVE‑2026‑3608 in Kea DHCP servers, urging immediate patching or TLS configuration, but does not provide PoC or exploit details.
ThreatCluster[verified]@threatclusterDisclosure
A new critical vulnerability (CVE‑2026‑3608) in ISC Kea DHCP servers has been disclosed. It permits remote unauthenticated attackers to crash servers, potentially disrupting IP allocation for millions of users.
Open Source Security mailing list@oss_securityDisclosure
A new stack overflow vulnerability (CVE-2026-3608) was disclosed in Kea DHCP daemons, causing a crash when a malicious message is sent to the API or HA listener.
Gray Hats@the_yellow_fallPatch
ISC alerts about a high‑severity stack overflow in Kea DHCP (CVE‑2026‑3608) that can crash services, urging users to upgrade to version 3.0.3 to apply the patch.
Ferramentas Linux@Cezar_H_LinuxDisclosure
A stack overflow vulnerability in Kea DHCP’s kea‑ctrl‑agent, dhcp4, and dhcp6 modules allows attackers to crash the service remotely. Further details are referenced via an external URL.
iototsecnews@iototsecnewsDisclosure
The post announces Kea DHCP CVE‑2026‑3608, a stack‑overflow vulnerability that can cause a complete service denial, and urges vigilance.
CVEarity@CVEarityGeneral
A brief tweet announcing CVE-2026-3608 with a severity score of 7.5, but lacking details on exploitation, vulnerability characteristics, or mitigation.