---
id: CVE-2025-11232
title: >-
  To trigger the issue, three configuration parameters must have specific
  settings: "hostname-char-set" must be left at the default setting, which is
  "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default); and
  "ddns-qual…
summary: >-
  To trigger the issue, three configuration parameters must have specific
  settings: "hostname-char-set" must be left at the default setting, which is
  "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default); and
  "ddns-qual…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-823
published: '2025-10-29'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11232'
references:
  - url: 'https://kb.isc.org/docs/cve-2025-11232'
    label: security-officer@isc.org
  - url: 'http://www.openwall.com/lists/oss-security/2025/10/29/5'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00424
epssPercentile: 0.34345
ingestedAt: '2026-09-30T23:29:32.457Z'
---

## Overview

To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default); and "ddns-qualifying-suffix" must *NOT* be empty (the default is empty). DDNS updates do not need to be enabled for this issue to manifest. A client that sends certain option content would then cause kea-dhcp4 to exit unexpectedly.
This issue affects Kea versions 3.0.1 through 3.0.1 and 3.1.1 through 3.1.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
