CVE-2025-32801

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
28/05/2025
Last modified:
29/05/2025

Description

Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths.<br /> This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.

References to Advisories, Solutions, and Tools