> ) Security Issues 3.1) Local Privilege Escalation by Injecting a Hook Library via the set-config Command (CVE-2025-32801) 3.2) Arbitrary File Overwrite via config-write Command (CVE-2025-32802) 3.3) Redirection of Log Files to Arbitrary Paths (shared CVE with 3.2) 3.4) Service Spoofing with Sockets in /tmp (shared CVE with 3.2) 3.5) Denial-of-Service issues with Sockets in /tmp (shared CVE with 3.2) 3.6) World-Readable DHCP Lease Files in /var/lib/kea/*.cvs (CVE-2025-32803) 3.7) World-Readable Kea Log Files (shared CVE with 3.6)
So CADT all over. Why fix old bugs when you can introduce new ones.
bogantech•8mo ago