---
title: "CVE-2025-32802\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-32802?format=md
keywords: index, follow
---

# CVE-2025-32802

Publication date 28 May 2025

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.1 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2025-32802?format=md#impact-score)

Toggle side navigation

## Description

Kea configuration and API directives can be used to overwrite arbitrary
files, subject to permissions granted to Kea. Many common configurations
run Kea as root, leave the API entry points unsecured by default, and/or
place the control sockets in insecure paths.
This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2,
and 2.7.0 through 2.7.8.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2025-32802?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| isc-kea | 25.10 questing | Fixed 2.6.3-1 |
| 25.04 plucky | Ignored end of life, was ignored [backport too intrusive] |
| 24.10 oracular | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Ignored backport too intrusive |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

The changes in the new version are massive and restrict
configuration and data files to a specific directory set at
build time. This may introduce a regression in stable releases
depending on how existing installations are configured.
On Debian and Ubuntu on noble+, the daemons are run as non-root,
and are protected by AppArmor. These hardening measures
mitigate this vulnerability.
In addition, access to the RESTful API is restricted to
authenticated users.
AppArmor profile was introduced in (2.2.0-3) (noble+)
RESTful API restriction was introduced in (2.2.0-8) (noble+)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.1 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | Low |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.1 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-32802)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-32802)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-32802)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-32802)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-32802>
* <https://www.openwall.com/lists/oss-security/2025/05/28/7>
* <https://www.openwall.com/lists/oss-security/2025/05/28/8>
