An update that solves three vulnerabilities can now be installed.. # Security update for kea Announcement ID: SUSE-SU-2026:0907-1 Release Date: 2026-03-17T16:32:34Z Rating: important References: * bsc#1243240 Cross-References: * CVE-2025-32801 * CVE-2025-32802 * CVE-2025-32803 CVSS scores: * CVE-2025-32801 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-32801 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-32801 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-32802 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-32802 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-32802 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-32803 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-32803 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2025-32803 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for kea fixes the following issues: Update to release 2.6.3 (bsc#1243240): * CVE-2025-32801: Loading a malicious hook library can lead to local privilege escalation. * CVE-2025-32802: Insecure handling of file paths allows multiple local attacks. * CVE-2025-32803: Insecure file permissions can result in confidential information leakage. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: *Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-907=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-907=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 s390x x86_64) * python3-kea-2.6.3-150700.3.3.5 * kea-debugsource-2.6.3-150700.3.3.5 * kea-debuginfo-2.6.3-150700.3.3.5 * Server Applications Module 15-SP7 (aarch64 s390x x86_64) * libkea-eval69-2.6.3-150700.3.3.5 * kea-devel-2.6.3-150700.3.3.5 * libkea-dhcpsrv111-2.6.3-150700.3.3.5 * libkea-cc68-debuginfo-2.6.3-150700.3.3.5 * libkea-process74-debuginfo-2.6.3-150700.3.3.5 * kea-debugsource-2.6.3-150700.3.3.5 * libkea-util86-debuginfo-2.6.3-150700.3.3.5 * kea-hooks-2.6.3-150700.3.3.5 * libkea-stats41-2.6.3-150700.3.3.5 * libkea-dhcp++92-2.6.3-150700.3.3.5 * libkea-dns++57-debuginfo-2.6.3-150700.3.3.5 * libkea-tcp19-2.6.3-150700.3.3.5 * libkea-util-io0-2.6.3-150700.3.3.5 * libkea-cfgclient66-2.6.3-150700.3.3.5 * kea-debuginfo-2.6.3-150700.3.3.5 * libkea-dhcpsrv111-debuginfo-2.6.3-150700.3.3.5 * libkea-database62-debuginfo-2.6.3-150700.3.3.5 * libkea-mysql71-debuginfo-2.6.3-150700.3.3.5 * libkea-cfgclient66-debuginfo-2.6.3-150700.3.3.5 * libkea-dns++57-2.6.3-150700.3.3.5 * libkea-util86-2.6.3-150700.3.3.5 * kea-2.6.3-150700.3.3.5 * kea-hooks-debuginfo-2.6.3-150700.3.3.5 * libkea-dhcp_ddns57-2.6.3-150700.3.3.5 * libkea-stats41-debuginfo-2.6.3-150700.3.3.5 * libkea-tcp19-debuginfo-2.6.3-150700.3.3.5 * libkea-d2srv47-2.6.3-150700.3.3.5 * libkea-http72-2.6.3-150700.3.3.5 * libkea-dhcp_ddns57-debuginfo-2.6.3-150700.3.3.5 * libkea-log61-debuginfo-2.6.3-150700.3.3.5 * libkea-pgsql71-2.6.3-150700.3.3.5 * libkea-exceptions33-2.6.3-150700.3.3.5 * libkea-pgsql71-debuginfo-2.6.3-150700.3.3.5 * libkea-dhcp++92-debuginfo-2.6.3-150700.3.3.5 * libkea-cryptolink50-2.6.3-150700.3.3.5 *libkea-eval69-debuginfo-2.6.3-150700.3.3.5 * libkea-d2srv47-debuginfo-2.6.3-150700.3.3.5 * libkea-hooks100-debuginfo-2.6.3-150700.3.3.5 * libkea-cryptolink50-debuginfo-2.6.3-150700.3.3.5 * libkea-log61-2.6.3-150700.3.3.5 * libkea-asiodns49-debuginfo-2.6.3-150700.3.3.5 * libkea-exceptions33-debuginfo-2.6.3-150700.3.3.5 * libkea-hooks100-2.6.3-150700.3.3.5 * libkea-database62-2.6.3-150700.3.3.5 * libkea-asiolink72-debuginfo-2.6.3-150700.3.3.5 * libkea-http72-debuginfo-2.6.3-150700.3.3.5 * libkea-util-io0-debuginfo-2.6.3-150700.3.3.5 * libkea-asiolink72-2.6.3-150700.3.3.5 * libkea-cc68-2.6.3-150700.3.3.5 * libkea-process74-2.6.3-150700.3.3.5 * libkea-asiodns49-2.6.3-150700.3.3.5 * libkea-mysql71-2.6.3-150700.3.3.5 * Server Applications Module 15-SP7 (noarch) * kea-doc-2.6.3-150700.3.3.5 ## References: * https://www.suse.com/security/cve/CVE-2025-32801.html * https://www.suse.com/security/cve/CVE-2025-32802.html * https://www.suse.com/security/cve/CVE-2025-32803.html * https://bugzilla.suse.com/show_bug.cgi?id=1243240 . Update for Kea addresses critical issues, including local privilege escalation and information leakage risks in SUSE.. Kea Security Update, SUSE Important Security, Local Privilege Escalation, Information Leakage Risk, Insecure File Permissions. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.