3 ms·
Looking at the CVE history, first "LTS" release 3.0.0 was quickly replaced by 3.0.1 https://kb.isc.org/docs/cve-2025-40779 https://kb.isc.org/docs/cve-2025-407
by guerby 10mo ago
Looking at the CVE history, first "LTS" release 3.0.0 was quickly replaced by 3.0.1
https://kb.isc.org/docs/cve-2025-40779 https://kb.isc.org/docs/cve-2025-40779
"CVE-2025-40779: Kea crash upon interaction between specific client options and subnet selection"
https://github.com/isc-projects/kea/commit/0afd42b5dfb2e547b3c25023953892c1e578aba3 https://github.com/isc-projects/kea/commit/0afd42b5dfb2e547b...
unprotected null pointer use, kea is in C++
- bayindirh 10mo agoShall we call Rust Evangelism Task Force and Rewrite in Rust in 3 femtoseconds?
- vpShane 10mo agoActually, yes, that'd be great!
- HackerThemAll 10mo agohttps://github.com/bluecatengineering/dora https://github.com/bluecatengineering/dora
- HackerThemAll 10mo agoAll software from ISC was/is littered with security vulnerabilities. BIND is in the same hall of shame as Sendmail.