CVE Alert: CVE-2026-3608 - ISC - Kea - RedPacket Security

**Risk verdict:** High availability risk: a network-reachable flaw with no privileges required could let an unauthenticated actor crash Kea daemons, so treat

RedPacket Security

- LAN on eth0: #Kea #DHCP serving internal hosts
- WAN on eth0.3: DHCP client talking to ISP

Kea: „I don't care about VLAN tagging, give me all your packets for my raw socket. By the way, how about using this nice internal LAN address for my hosts WAN interface?“

https://gitlab.isc.org/isc-projects/kea/-/issues/1117

At least the issue has recently been closed (after six years). Now waiting for an updated package to arrive. Or an alternative - whatever comes first. Any recommendations apart from dnsmasq?

Mix of physical and virtual interfaces (VLAN) does not work (#1117) · Issues · ISC Open Source Projects / Kea · GitLab

Describe the bug Setting up KEA DHCP server on a system to listen to a physical interface and one or multiple virtual interfaces causes wrong IP pools to...

GitLab

@KimiEO Dankon!
Mi estudas en #Duolingo . Mi estudis mallonga en #Lernu antaŭ multaj jarjoj.

#Esperanto estis prezentita al mi en #JuizDeFora pere de la #EsperantoKultura Asocio (#KEA).

Mi estas aŭtismulo ankaŭ, kaj dupolusalo.

En kiu ŝtato vi loĝas?

#Esperanto

#opnsense migration: Complete.

The preparation legwork made lots of things easier, but even once swapped I realized I had about 5% of it wrong.

I also still had a #virtualip in the config from the first hour of having it running when I was trying to migrate away from my VIPs in a #fortigate, which are a TOTALLY different thing.

NAT Reflection eluded me for a good hour, but all the VLANs behave, #kea DHCP seems to be all up and running and #ntopNG is much nicer than some of the built in systems of #fortinet.

#IDS feels innately trickier than before but pros and cons.

@FritzAdalis I'll have to look to see if that works with #Kea as #ISC is being phased out. But it's an interseting posibility.

Most of my knowledge came from searching through feedback on the PF/OPN subreddits.

the majestic #kea. quick photo break between it trying to take of the car antenna (expected) and biting me in the ankle (my fault. I was wearing red socks and they looked interesting. I am 99% sure it didn't hurt me on purpose)
Don't feed the kea!
#photography #wildlifephotography #travelphotography #birds #aotearoa #newzealand

Finally, I have some good enough DHCP server.

It is a kea from ISC – the successor of EOLed dhcpd.

The moment, when I switched re0 interface configuration from DHCP to static IP and rebooted the server — was the most touching. The second one — when I disabled DHCP server in the D-Link router, started kea and restarted the router  

Fortunately, the lines from connecting phone appeared in the kea log after some lenghty seconds  

#SelfHosting #dhcp #kea #DHCPv4