This update for kea fixes the following issues:
Update to release 2.6.3 (bsc#1243240):
* CVE-2025-32801: Fixed loading a malicious hook library can lead to local
privilege escalation.
* CVE-2025-32802: Fixed insecure handling of file paths allows multiple local
attacks.
* CVE-2025-32803: Fixed insecure file permissions can result in confidential
information leakage.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1091=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-1091=1 openSUSE-SLE-15.6-2026-1091=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1091=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libkea-util86-debuginfo-2.6.3-150600.13.6.1
* python3-kea-2.6.3-150600.13.6.1
* libkea-dhcpsrv111-2.6.3-150600.13.6.1
* libkea-exceptions33-debuginfo-2.6.3-150600.13.6.1
* libkea-cfgclient66-debuginfo-2.6.3-150600.13.6.1
* libkea-eval69-2.6.3-150600.13.6.1
* libkea-log61-2.6.3-150600.13.6.1
* kea-debuginfo-2.6.3-150600.13.6.1
* libkea-util86-2.6.3-150600.13.6.1
* kea-hooks-debuginfo-2.6.3-150600.13.6.1
* libkea-asiodns49-debuginfo-2.6.3-150600.13.6.1
* libkea-dns++57-2.6.3-150600.13.6.1
* libkea-cryptolink50-2.6.3-150600.13.6.1
* libkea-process74-debuginfo-2.6.3-150600.13.6.1
* libkea-dhcp_ddns57-debuginfo-2.6.3-150600.13.6.1
* libkea-cryptolink50-debuginfo-2.6.3-150600.13.6.1
* kea-devel-2.6.3-150600.13.6.1
* libkea-stats41-2.6.3-150600.13.6.1
* libkea-util-io0-debuginfo-2.6.3-150600.13.6.1
* libkea-hooks100-debuginfo-2.6.3-150600.13.6.1
* libkea-process74-2.6.3-150600.13.6.1
* libkea-stats41-debuginfo-2.6.3-150600.13.6.1
*...
Read the Full Advisory* bsc#1243240
## References:
* https://www.suse.com/security/cve/CVE-2025-32801.html
* https://www.suse.com/security/cve/CVE-2025-32802.html
* https://www.suse.com/security/cve/CVE-2025-32803.html
* https://bugzilla.suse.com/show_bug.cgi?id=1243240
Get the latest Linux and open source security news straight to your inbox.