# Kea 3.3.2 Release Notes, September 30, 2026 Welcome to Kea 3.3.2, a release of the 3.3 development series. As with any other development release, use this with caution: development releases are not recommended for production use. Kea is a DHCP implementation developed by Internet Systems Consortium (ISC) that features DHCPv4 and DHCPv6 servers with DNS update and a REST API; optional database support (MySQL and PostgreSQL); optional RADIUS, YANG/NETCONF, and Kerberos GSS-TSIG support; and much more. Kea provides extensive management capabilities, including but not limited to: TLS support, Role-Based Access Control, run-time configuration monitoring and updates via a REST API, host reservations, and client classification. The text below references issue numbers. For more details, visit the Kea GitLab page at https://gitlab.isc.org/isc-projects/kea/-/issues. For details about Docker issues, visit the page at https://gitlab.isc.org/isc-projects/kea-docker/-/issues/. For details about packaging, visit the page at https://gitlab.isc.org/isc-projects/kea-packaging/-/issues/. The following bug fixes and features have been implemented since the previous release: 1. **Dynamic DNS improvements**: Related DDNS name-change requests from kea-dhcp4 and kea-dhcp6 are now sent to kea-dhcp-ddns as a single message, guaranteeing they're processed in the order they were generated [#3005]. kea-dhcp-ddns no longer starts a duplicate transaction for the same FQDN or IP address — previously this was guarded only by comparing DHCID values [#4585] — and it no longer schedules unnecessary DDNS removals when a lease is simply renewed [#4794]. Better error handling when sending DNS updates [#4644, #4646]. Modified kea-dhcp4 and kea-dhcp6 to avoid scheduling unnecessary DDNS entry removals when renewing leases [#4794]. 2. **OpenSSL 4.0 support**: Kea can now be built against OpenSSL 4.0.x [#4673]. 3. **Statistics**: The `perfmon-get-all-durations` command in libdhcp_perfmon hook now reports `total-duration-usecs` and `mean-duration-usecs` as distinct columns instead of one concatenated name [#4797]. 4. **Bug fixes**: IOFetch no longer hangs when an asynchronous I/O failure occurs with no timeout configured — it now reports IO_ERROR instead [#4633]. Kea no longer crashes in perfdhcp, the host_cache hook, kea-dhcp4, kea-dhcp6, kea-dhcp-ddns, or kea-netconf when built with -D_GLIBCXX_ASSERTIONS (thanks to Joseph Bisch for reporting) [#4708]. Long VIVSO vendor-option values are now unpacked correctly [#4770]. Configuration and agent files containing embedded null characters no longer confuse the lexical analyzers [#4739]. Configuration values containing quote characters are now safely escaped in YANG XPath predicates, so they can no longer break or redirect the underlying sysrepo path [#4668]. kea-dhcp6 lease-lifetime fix on reuse: When reusing an expired lease, kea-dhcp6 now correctly recalculates the lease lifetimes instead of reusing the expired lease's values, which could previously cause it to advertise a lease shorter than min-valid-lifetime [#4591]. PostgreSQL config-backend schema fix: The dhcp4_pool, dhcp6_pool, and dhcp6_pd_pool tables were missing cascading update/delete on their subnet_id foreign keys, which could leave orphaned pool rows after deleting or renumbering a subnet. Fixed [#4323]. Fixed IOFetch so asynchronous I/O failures invoke the completion callback with IO_ERROR instead of hanging when no timeout is configured [#4633]. Fixed a small leak in the HTTP connection establishment code [#4767]. Addressed a slight inconsistent behavior of the hardware type in leases processing [#4631]. Fixed a potential race condition in `wipe-leases4`, `wipe-leases6` [#4648]. Fixed comparison code for handling option defitions configurations [#4731]. Configuring 'match-client-id' to false has now no effect when the query hardware address is empty. Thank you to Qifan Zhang from Palo Alto Networks for reporting the issue [#4535]. 5. **Documentation**: The ARM now clarifies that client-class definitions are shareable among servers when using a configuration backend [#4372]. Added a note about restricting HA listener [#4718]. 6. **Performance**: A marginally more effective code was implemented for handling Boost ASIO sockets [#4729]. 7. **Build improvements**: The obsolete Vagrant code was removed [#4801]. 8. libdhcp_perfmon duration reporting fix: perfmon-get-all-durations now reports total-duration-usecs and mean-duration-usecs as distinct columns instead of one concatenated name [#4797]. 9. **Testing**: Fixed potential problem with running interface tests on FreeBSD [#4572]. Fixed potential tests in Memfile lease manager tests [#4102]. Fixed a problem in a Decline Test that was failing if it was run by itself more than once [#3810]. Fixed undefined behavior reported by fuzzing [#4768]. The valgrind suppression file can now match objects by wildcard names [#4699]. Fixed couple HTTP tests failing on RHEL 8 [#4766]. Addressed several long processing times, as reported by fuzzing [#4366,#4672]. Extra checks added for hardware address checks in host reservations [#4519]. Test timeouts were increased for unit-tests [#4744]. After many years of useful service, we decided to retire our Coverity Scan service. Thank you for all the bugs reported over the years [#4484]. Fixed compilation issues when enabling tests [#4776]. ## Incompatible Changes There are no incompatible changes introduced in this release. ## License This version of Kea is released under the Mozilla Public License, version 2.0. https://www.mozilla.org/en-US/MPL/2.0 Some Kea hook libraries are provided under the MPL 2.0; others are licensed with the [Kea Hooks Basic Commercial End User License](https://www.isc.org/kea-premium-license/). The source for each hook library includes the applicable license. ## Download Pre-built ISC packages for current versions of the most popular Linux operating systems are available at: https://cloudsmith.io/~isc/repos/ Pre-built Docker images, as well as Docker files, are available. For details, see: https://gitlab.isc.org/isc-projects/kea-docker The Kea source and PGP signature for this release may be downloaded from: https://www.isc.org/download The signature was generated with the ISC code-signing key, which is available at: https://www.isc.org/pgpkey ISC provides detailed documentation, including installation instructions and usage tutorials, in the Kea Administrator Reference Manual. Documentation is included with the installation or at https://kea.readthedocs.io/en/latest/index.html in HTML, PDF, or EPUB formats. ISC maintains a public open source code tree, wiki, issue tracking system, milestone planner, and roadmap at https://gitlab.isc.org/isc-projects/kea. Limitations and known issues with this release can be found at https://gitlab.isc.org/isc-projects/kea/-/wikis/known-issues-list. We ask users of this software to please let us know how it worked for you and what operating system you tested on. Feel free to share your feedback on the Kea Users mailing list (https://lists.isc.org/mailman/listinfo/kea-users). We would also like to hear whether the documentation is adequate and accurate. Please open tickets in the Kea GitLab project for bugs, documentation omissions and errors, and enhancement requests. We want to hear from you even if everything worked. ## Support Professional support for Kea is available from ISC. We encourage all professional users to consider this option; Kea maintenance is funded with support subscriptions. For more information on ISC's Kea software support, see https://www.isc.org/support/. Free best-effort support is provided by our user community via a mailing list. Information on all public email lists is available at https://www.isc.org/community/mailing-list. If you have any comments or questions about working with Kea, please share them to the Kea Users list (https://lists.isc.org/mailman/listinfo/kea-users). Bugs and feature requests may be submitted via GitLab at https://gitlab.isc.org/isc-projects/kea/-/issues. ## Changes The following summarizes the changes since the previous release. 2567. [bug] erichu Fixed the perfmon-get-all-durations result-set so total-duration-usecs and mean-duration-usecs are reported as separate column names. (Gitlab #4797) 2566. [bug] tmark Added missing cascade delete and update actions to the subnet-id foreign key constraints on the dhcp4_pool, dhcp6_pool and dhcp6_pd_pool tables in the postgresql schema. (Gitlab #4323) 2565. [bug] fdupont When reusing an expired lease, kea-dhcp6 now correctly recalculates the lease life times. Prior to this it was using the values from the expired lease. (Gitlab #4591) 2564. [doc] tmark Updated kea-dhcp4 and kea-dhcp6 ARM sections to state that client-class definitions are shareable among servers in config back end. (Gitlab #4372) 2563. [bug] tmark Related name change requests (NCRs), are now sent by kea-dhcp4 and kea-dhcp6 in a single message to kea-dhcp-ddns. This ensures that kea-dhcp-ddns processes them in the order they were received. (Gitlab #3005) 2562. [bug] wlodek,tmark Quoted YANG XPath list-key predicates safely so configuration values containing quotes no longer break or retarget sysrepo paths. (Gitlab #4668) 2561. [func] tmark Modified kea-dhcp4 and kea-dhcp6 to avoid scheduling unnecessary DDNS entry removals when renewing leases. (Gitlab #4794) 2560. [bug] wlodek Fixed IOFetch so asynchronous I/O failures invoke the completion callback with IO_ERROR instead of hanging when no timeout is configured. (Gitlab #4633) 2559. [bug] fdupont Made lexical analyzers more robust with null characters in input, e.g. in server or agent configuration files. (Gitlab #4739) 2558. [build] fdupont Added OpenSSL 4.0.x support. (Gitlab #4673) 2557. [bug] tmark Modified kea-dhcp-ddns to avoid starting a transaction for a request if there is already a transaction for the request's FQDN or ip address. Prior to this it used the DHCID to guard against concurrent work. (Gitlab #4585) 2556. [func]* fdupont Configuring 'match-client-id' to false has now no effect when the query hardware address is empty. Thank you to Qifan Zhang from Palo Alto Networks for reporting the issue. (Gitlab #4535) 2555. [build] razvan The library version numbers have been bumped up for the Kea 3.3.2 development release. (Gitlab #4822) 2554. [bug] razvan Fixed improper unpacking of long VIVSO options. (Gitlab #4770) 2553. [bug] razvan Fixed bugs related to out of bound container access which can cause Kea to crash if -D_GLIBCXX_ASSERTIONS flag is used at compilation time. This affected perfdhcp, host_cache hook library, kea-dhcp4, kea-dhcp6, kea-dhcp-ddns and kea-netconf. Thank you to Joseph Bisch (joseph.bisch@gmail.com) for reporting this issue. (Gitlab #4708) Thank you again to everyone who assisted us in making this release possible. We look forward to receiving your feedback.