Описание
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.
A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit an integer underflow and an out-of-bounds read vulnerability by calling gss_accept_sec_context() on a system with a NegoEx mechanism registered. This can lead to the process terminating, resulting in a Denial of Service (DoS).
Отчет
This Moderate impact denial of service flaw in MIT Kerberos 5 (krb5) allows an unauthenticated remote attacker to trigger an integer underflow and out-of-bounds read. This vulnerability, which can lead to process termination, specifically affects systems where the NegoEx mechanism is registered and gss_accept_sec_context() is called. While Kerberos is a fundamental service, the prerequisite of a registered NegoEx mechanism limits the attack surface.
Меры по смягчению последствий
To mitigate this issue, ensure that the NegoEx mechanism is not registered in the /etc/gss/mech configuration file. Removing the corresponding entry from this file will prevent the vulnerable code path from being activated. This action may impact services that rely on the NegoEx GSS-API mechanism. A restart of affected Kerberos-dependent services may be required for the change to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | krb5 | Fix deferred | ||
| Red Hat Enterprise Linux 7 | krb5 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Enterprise Linux 10 | krb5 | Fixed | RHSA-2026:19145 | 19.05.2026 |
| Red Hat Enterprise Linux 8 | krb5 | Fixed | RHSA-2026:16799 | 13.05.2026 |
| Red Hat Enterprise Linux 9 | krb5 | Fixed | RHSA-2026:19357 | 19.05.2026 |
| Red Hat Enterprise Linux 9 | krb5 | Fixed | RHSA-2026:19357 | 19.05.2026 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | krb5 | Fixed | RHSA-2026:24685 | 09.06.2026 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | krb5 | Fixed | RHSA-2026:24686 | 09.06.2026 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | krb5 | Fixed | RHSA-2026:24683 | 09.06.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
5.9 Medium
CVSS3
Связанные уязвимости
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underf ...
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.
5.9 Medium
CVSS3