Описание
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
A memory leak flaw was found in krb5 in /krb5/src/lib/gssapi/krb5/k5sealv3.c. This issue can lead to a denial of service through memory exhaustion.
Отчет
In the file k5sealv3.c, a variable named plain is defined and its address is passed to alloc_data. Inside alloc_data, plain is called data, and calloc allocates memory for ptr, which is assigned to data->data. If an if condition evaluates to true, the program jumps to an error label using a goto statement, leaving the memory allocated to plain unused and unreleased, leading to a memory leak defect.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 10 | krb5 | Not affected | ||
Red Hat Enterprise Linux 6 | krb5 | Out of support scope | ||
Red Hat Enterprise Linux 7 | krb5 | Out of support scope | ||
Red Hat Enterprise Linux 8 | krb5 | Fixed | RHSA-2024:3268 | 22.05.2024 |
Red Hat Enterprise Linux 9 | krb5 | Fixed | RHSA-2024:9331 | 12.11.2024 |
Red Hat Enterprise Linux 9 | krb5 | Fixed | RHSA-2024:9331 | 12.11.2024 |
Показывать по
Дополнительная информация
Статус:
5.9 Medium
CVSS3
Связанные уязвимости
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in / ...
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
5.9 Medium
CVSS3