On 2025-08-27 10:22 PM, Salvatore Bonaccorso wrote:
> Source: isc-kea
> Version: 2.6.3-2
> 
> The following vulnerability was published for isc-kea.
> 
> CVE-2025-40779[0]:
> | Kea crash upon interaction between specific client options and
> | subnet selection
> 
> 
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
> 
> For further information see:
> 
> [0] https://security-tracker.debian.org/tracker/CVE-2025-40779
>     https://www.cve.org/CVERecord?id=CVE-2025-40779
> [1] https://kb.isc.org/docs/cve-2025-40779
> [2] 
> https://gitlab.isc.org/isc-projects/kea/-/commit/b25d7e8a81273e4099bf6c7f639ed774de2f3d08

Hi Salvatore,

>From the CVE itself, looks like version 2.6.3-2 is not affected by the
vulnerability. There is an older version in oldstable, which again
according to the CVE is "likely unaffected".

Do you think we should mark the oldstable version affected by this bug?

Thanks,

Paride

Reply via email to