CVE-2026-107778
- EPSS 0.42%
- Veröffentlicht 08.10.2026 20:15:54
- Zuletzt bearbeitet 09.10.2026 12:17:09
MIT Kerberos 5 (krb5) through 1.22.2 contains a NULL pointer dereference in make_cred_list() in rd_cred.c that allows authenticated Kerberos clients to crash services by sending mismatched KRB-CRED arrays. Attackers can send forwarded credentials wit...
CVE-2026-107708
- EPSS 0.52%
- Veröffentlicht 08.10.2026 20:15:53
- Zuletzt bearbeitet 08.10.2026 21:33:42
MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can ...
CVE-2026-40355
- EPSS 0.61%
- Veröffentlicht 28.04.2026 00:00:00
- Zuletzt bearbeitet 14.07.2026 13:18:50
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, cau...
CVE-2026-40356
- EPSS 0.6%
- Veröffentlicht 28.04.2026 00:00:00
- Zuletzt bearbeitet 08.07.2026 12:48:10
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote att...
CVE-2025-24528
- EPSS 0.53%
- Veröffentlicht 16.01.2026 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.
CVE-2024-37371
- EPSS 1.86%
- Veröffentlicht 28.06.2024 23:15:11
- Zuletzt bearbeitet 12.05.2026 12:16:51
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
CVE-2024-37370
- EPSS 0.75%
- Veröffentlicht 28.06.2024 22:15:02
- Zuletzt bearbeitet 12.05.2026 12:16:51
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.
CVE-2024-26458
- EPSS 0.82%
- Veröffentlicht 29.02.2024 01:44:18
- Zuletzt bearbeitet 23.05.2025 15:39:31
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
CVE-2024-26461
- EPSS 1.13%
- Veröffentlicht 29.02.2024 01:44:18
- Zuletzt bearbeitet 23.05.2025 15:30:30
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
CVE-2024-26462
- EPSS 0.44%
- Veröffentlicht 29.02.2024 01:44:18
- Zuletzt bearbeitet 25.03.2025 20:15:21
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.