# Kea 3.2.1 Maintenance Release Notes, September 30, 2026 Welcome to Kea 3.2.1, a maintenance release of the stable 3.2 series. This supersedes the previous release, version 3.2.0. Kea is a DHCP implementation developed by Internet Systems Consortium (ISC) that features DHCPv4 and DHCPv6 servers with DNS update and a REST API; optional database support (MySQL and PostgreSQL); optional RADIUS, YANG/NETCONF, and Kerberos GSS-TSIG support; and much more. Kea provides extensive management capabilities, including but not limited to: TLS support, Role-Based Access Control, run-time configuration monitoring and updates via a REST API, host reservations, and client classification. The text below references issue numbers. For more details, visit the Kea GitLab page at https://gitlab.isc.org/isc-projects/kea/-/issues. For details about Docker issues, visit the page at https://gitlab.isc.org/isc-projects/kea-docker/-/issues/. For details about packaging, visit the page at https://gitlab.isc.org/isc-projects/kea-packaging/-/issues/. The following changes and bug fixes have been implemented since the previous release: 1. **Bug fix**: Related name change requests (NCRs) are now sent by `kea-dhcp4` and `kea-dhcp6` in a single message to `kea-dhcp-ddns`. This ensures that `kea-dhcp-ddns` processes them in the order they were received [#4806, #3005]. 2. **Bug fix**: `kea-dhcp-ddns` was modified to avoid starting a transaction for a request if there is already a transaction for the request's FQDN or IP address. Previously, the DHCID was used to guard against concurrent work [#4805,#4585]. 3. **Bug fix**: `kea-dhcp4` and `kea-dhcp6` were modified to avoid scheduling unnecessary DDNS entry removals when renewing leases [#4804, #4794]. 4. **Bug fix**: We have made the lexical analyzers more robust when there are null characters in the input, e.g. in server or agent configuration files [#4795,#4739]. 5. **Bug fix**: We fixed several MySQL host backend problems [#4691,#4753]. 6. **Bug fix**: We added better error handling for MySQL [#4754,#4658]. 7. **Bug fix**: We improved handling of special characters in values written to a memfile lease database [#4787, #4393, #4521]. 8. **Bug fix**: We fixed bugs related to out-of-bound container access, which could cause Kea to crash if the -D_GLIBCXX_ASSERTIONS flag was used at compilation time. This affected `perfdhcp`, the `host_cache` hook library, `kea-dhcp4`, `kea-dhcp6`, `kea-dhcp-ddns` and `kea-netconf`. Thank you to Joseph Bisch (joseph.bisch@gmail.com) for reporting this issue [#4783,#4741,#4708]. 9. **Bug fix**: We made parsing of DHCPv6 relayed messages stricter: now, truncated RELAY-FORW and RELAY-REPLY headers cause the whole message to be dropped. Thank you to Qifan Zhang from Palo Alto Networks for reporting the issue [#4752,#4560,#4735]. 10. **Bug fix**: The broadcast flag in DHCPNAK responses is now set to relayed DHCPREQUEST queries as required by RFC 2131 4.3.2. Thank you to Florian Krieger from Frauscher Sensor Technology Group GmbH for reporting the issue [#4751,#4424]. 11. **Bug fix**: We fixed an issue in debug-level logging of dropped packets that could cause the Kea server to crash under heavy load. This applies to both `kea-dhcp4` and `kea-dhcp6` [#4750,#4755,#4719,#4748]. 12. **Bug fix**: We removed spurious DHCP_RECEIVE4_UNKNOWN and DHCP_RECEIVE6_UNKNOWN warnings sent, for instance, when a command was received. This bug was introduced in the 3.2.0 release [#4749, #4674]. 13. **Build improvements**: We added compatibility with OpenSSL 4.0 [#4756,#4673]. ## Incompatible Changes There are no incompatible changes in this release. ## Known Issues There are no significant known issues. ## License This version of Kea is released under the Mozilla Public License, version 2.0. https://www.mozilla.org/en-US/MPL/2.0 Some Kea hook libraries are provided under the MPL 2.0; others are licensed with the [Kea Hooks Basic Commercial End User License](https://www.isc.org/kea-premium-license/). The source for each hook library includes the applicable license. ## Download Pre-built ISC packages for current versions of the most popular Linux operating systems are available at: https://cloudsmith.io/~isc/repos/ Pre-built Docker images as well as Docker files are available. For details, see: https://gitlab.isc.org/isc-projects/kea-docker The Kea source and PGP signature for this release may be downloaded from: https://www.isc.org/download The signature was generated with the ISC code-signing key, which is available at: https://www.isc.org/pgpkey ISC provides detailed documentation, including installation instructions and usage tutorials, in the Kea Administrator Reference Manual. Documentation is included with the installation or at https://kea.readthedocs.io/en/latest/index.html in HTML, PDF, or EPUB formats. ISC maintains a public open source code tree, wiki, issue tracking system, milestone planner, and roadmap at https://gitlab.isc.org/isc-projects/kea. Limitations and known issues with this release can be found at https://gitlab.isc.org/isc-projects/kea/-/wikis/known-issues-list. We ask users of this software to please let us know how it worked for you and what operating system you tested on. Feel free to share your feedback on the Kea Users mailing list (https://lists.isc.org/mailman/listinfo/kea-users). We would also like to hear whether the documentation is adequate and accurate. Please open tickets in the Kea GitLab project for bugs, documentation omissions and errors, and enhancement requests. We want to hear from you even if everything worked. ## Support Professional support for Kea is available from ISC. We encourage all professional users to consider this option; Kea maintenance is funded with support subscriptions. For more information on ISC's Kea software support, see https://www.isc.org/support/. Free best-effort support is provided by our user community via a mailing list. Information on all public email lists is available at https://www.isc.org/community/mailing-list. If you have any comments or questions about working with Kea, please share them to the Kea Users list (https://lists.isc.org/mailman/listinfo/kea-users). Bugs and feature requests may be submitted via GitLab at https://gitlab.isc.org/isc-projects/kea/-/issues. ## Changes The following summarizes the changes since the previous release: 2511. [bug] tmark Related name change requests (NCRs), are now sent by kea-dhcp4 and kea-dhcp6 in a single message to kea-dhcp-ddns. This ensures that kea-dhcp-ddns processes them in the order they were received. (Gitlab #4806, #3005) 2510. [bug] tmark Modified kea-dhcp-ddns to avoid starting a transaction for a request if there is already a transaction for the request's FQDN or ip address. Prior to this it used the DHCID to guard against concurrent work. (Gitlab #4805,#4585) 2509. [func] tmark Modified kea-dhcp4 and kea-dhcp6 to avoid scheduling unnecessary DDNS entry removals when renewing leases. (Gitlab #4804, #4794) 2508. [bug] fdupont Made lexical analyzers more robust with null characters in input, e.g. in server or agent configuration files. (Gitlab #4795,#4739) 2507. [build] fdupont Added OpenSSL 4.0.x support. (Gitlab #4756, #4673) 2506. [bug] tmark Improved handling of special characters in values written to memfile lease database. (Gitlab #4787, #4393) 2505. [bug] razvan, fdupont Fixed bugs related to out of bound container access which can cause Kea to crash if -D_GLIBCXX_ASSERTIONS flag is used at compilation time. This affected perfdhcp, host_cache hook library, kea-dhcp4, kea-dhcp6, kea-dhcp-ddns and kea-netconf. Thank you to Joseph Bisch (joseph.bisch@gmail.com) for reporting this issue. (Gitlab #4783,#4741,#4708) 2504. [bug] fdupont Made parsing of DHCPv6 relayed messages stricter: now truncated RELAY-FORW and RELAY-REPLY headers cause the whole message to be dropped. Thank you to Qifan Zhang from Palo Alto Networks for reporting the issue. (Gitlab #4752,#4560,#4735) 2503. [bug] fdupont Set the broadcast flag in DHCPNAK responses to relayed DHCPREQUEST queries as required by RFC 2131 4.3.2. Thank you to Florian Krieger from Frauscher Sensor Technology Group GmbH for reporting the issue. (Gitlab #4751,#4424) 2502. [bug] razvan,tmark Corrected MLM_MYSQL_FETCH_FAILURE to 1 so MySQL selectQuery and host lookups detect mysql_stmt_fetch errors instead of silently ignoring them. (Gitlab #4754,#4658) 2501. [bug] fdupont,tmark Fixed an issue in debug-level logging of dropped packets that could cause the server to crash under heavy load. Applies to both kea-dhcp4 and kea-dhcp6. (Gitlab #4750,#4755,#4719,#4748) 2500. [bug] fdupont,tmark Removed spurious DHCP_RECEIVE4_UNKNOWN and DHCP_RECEIVE6_UNKNOWN warnings sent for instance when a command is received. This bug was introduced in 3.2.0 release. (Gitlab #4749, #4674) 2499. [build] razvan The library version numbers have been bumped up for the Kea 3.2.1 stable release. (Gitlab #4811) 2498. [bug] tmark Improved handling of special characters in values written to memfile lease database. (Gitlab #4787,#4393) Thank you again to everyone who assisted us in making this release possible. We look forward to receiving your feedback.