This update for kea fixes the following issues:
Update to release 2.6.5.
Security issues fixed:
* CVE-2026-3608: stack overflow error via specially crafted message to the
kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons(bsc#1260380).
Other updates and bugfixes:
* A null dereference is now no longer possible when configuring the Control
Agent with a socket that lacks the mandatory socket-name entry.
* UNIX sockets are now created as group-writable.
* Corrected an issue in logging configuration when parsing "syslog:".
* Fixed crash when handling misconfigured global reservations.
* Support for recent versions of Sphinx has been added.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1548=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-1548=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1548=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libkea-log61-2.6.5-150600.13.9.1
* libkea-pgsql71-debuginfo-2.6.5-150600.13.9.1
* libkea-asiodns49-2.6.5-150600.13.9.1
* libkea-pgsql71-2.6.5-150600.13.9.1
* libkea-hooks102-2.6.5-150600.13.9.1
* kea-devel-2.6.5-150600.13.9.1
* kea-hooks-debuginfo-2.6.5-150600.13.9.1
* libkea-cryptolink50-2.6.5-150600.13.9.1
* libkea-cc69-debuginfo-2.6.5-150600.13.9.1
* libkea-http72-2.6.5-150600.13.9.1
* kea-debuginfo-2.6.5-150600.13.9.1
* libkea-d2srv47-2.6.5-150600.13.9.1
* libkea-http72-debuginfo-2.6.5-150600.13.9.1
* libkea-stats41-debuginfo-2.6.5-150600.13.9.1
* libkea-eval69-2.6.5-150600.13.9.1
* libkea-exceptions33-2.6.5-150600.13.9.1
* python3-kea-2.6.5-150600.13.9.1
* libkea-exceptions33-debuginfo-2.6.5-150600.13.9.1
* libkea-asiodns49-debuginfo-2.6.5-150600.13.9.1
* libkea-cfgclient67-2.6.5-150600.13.9.1
* libkea-database62-debuginfo-2.6.5-150600.13.9.1
* libkea-tcp19-debuginfo-2.6.5-150600.13.9.1
*...
Read the Full Advisory* bsc#1260380
## References:
* https://www.suse.com/security/cve/CVE-2026-3608.html
* https://bugzilla.suse.com/show_bug.cgi?id=1260380
Get the latest Linux and open source security news straight to your inbox.