Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2848-1

Опубликовано: 10 июл. 2026
Источник: suse-cvrf

Описание

Security update for krb5, krb5-mini

This update for krb5, krb5-mini fixes the following issues

  • CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131).
  • CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366).
  • CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367).

Список пакетов

Container bci/spack:latest
krb5-devel-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-core:latest
krb5-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-exporter:latest
krb5-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-jobservice:latest
krb5-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-portal:latest
krb5-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-registry:latest
krb5-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-registryctl:latest
krb5-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-trivy-adapter:latest
krb5-1.20.1-150600.11.19.1
Container private-registry/harbor-core:latest
krb5-1.20.1-150600.11.19.1
Container private-registry/harbor-exporter:latest
krb5-1.20.1-150600.11.19.1
Container private-registry/harbor-jobservice:latest
krb5-1.20.1-150600.11.19.1
Container private-registry/harbor-portal:latest
krb5-1.20.1-150600.11.19.1
Container private-registry/harbor-registry:latest
krb5-1.20.1-150600.11.19.1
Container private-registry/harbor-registryctl:latest
krb5-1.20.1-150600.11.19.1
Container private-registry/harbor-trivy-adapter:latest
krb5-1.20.1-150600.11.19.1
Container suse/kiosk/firefox-esr:latest
krb5-1.20.1-150600.11.19.1
Container suse/kiosk/pulseaudio:latest
krb5-1.20.1-150600.11.19.1
Container suse/kiosk/xorg-client:latest
krb5-1.20.1-150600.11.19.1
Container suse/kiosk/xorg:latest
krb5-1.20.1-150600.11.19.1
Container suse/ltss/sle15.6/bci-base-fips:latest
krb5-1.20.1-150600.11.19.1
Container suse/sle15:latest
krb5-1.20.1-150600.11.19.1
Image pr_15_7
krb5-1.20.1-150600.11.19.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
krb5-1.20.1-150600.11.19.1
krb5-32bit-1.20.1-150600.11.19.1
krb5-client-1.20.1-150600.11.19.1
krb5-devel-1.20.1-150600.11.19.1
krb5-plugin-preauth-otp-1.20.1-150600.11.19.1
krb5-plugin-preauth-pkinit-1.20.1-150600.11.19.1
SUSE Linux Enterprise Module for Server Applications 15 SP7
krb5-plugin-kdb-ldap-1.20.1-150600.11.19.1
krb5-server-1.20.1-150600.11.19.1
SUSE Linux Enterprise Server 15 SP6-LTSS
krb5-1.20.1-150600.11.19.1
krb5-32bit-1.20.1-150600.11.19.1
krb5-client-1.20.1-150600.11.19.1
krb5-devel-1.20.1-150600.11.19.1
krb5-plugin-kdb-ldap-1.20.1-150600.11.19.1
krb5-plugin-preauth-otp-1.20.1-150600.11.19.1
krb5-plugin-preauth-pkinit-1.20.1-150600.11.19.1
krb5-server-1.20.1-150600.11.19.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
krb5-1.20.1-150600.11.19.1
krb5-32bit-1.20.1-150600.11.19.1
krb5-client-1.20.1-150600.11.19.1
krb5-devel-1.20.1-150600.11.19.1
krb5-plugin-kdb-ldap-1.20.1-150600.11.19.1
krb5-plugin-preauth-otp-1.20.1-150600.11.19.1
krb5-plugin-preauth-pkinit-1.20.1-150600.11.19.1
krb5-server-1.20.1-150600.11.19.1

Описание

An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.


Затронутые продукты
Container bci/spack:latest:krb5-devel-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-core:latest:krb5-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-exporter:latest:krb5-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-jobservice:latest:krb5-1.20.1-150600.11.19.1

Ссылки

Описание

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.


Затронутые продукты
Container bci/spack:latest:krb5-devel-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-core:latest:krb5-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-exporter:latest:krb5-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-jobservice:latest:krb5-1.20.1-150600.11.19.1

Ссылки

Описание

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.


Затронутые продукты
Container bci/spack:latest:krb5-devel-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-core:latest:krb5-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-exporter:latest:krb5-1.20.1-150600.11.19.1
Container private-registry/1.2/harbor-jobservice:latest:krb5-1.20.1-150600.11.19.1

Ссылки