Security update for krb5
This update for krb5 fixes the following issues: - CVE-2024-37370: Confidential GSS krb5 wrap tokens with invalid plaintext Extra Count fields were erroneously accepted during unwrap (bsc#1227186) - CVE-2024-37371: Fixed invalid memory read when processing message tokens with invalid length fields (bsc#1227187) - CVE-2024-26458: Fixed memory leak at /krb5/src/lib/rpc/pmap_rmt.c (bsc#1220770) - CVE-2024-26461: Fixed memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c (bsc#1220771) - CVE-2024-26462: Fixed memory leak at /krb5/src/kdc/ndr.c (bsc#1220772)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for krb5 fixes the following issues: - CVE-2024-37370: Confidential GSS krb5 wrap tokens with invalid plaintext Extra Count fields were erroneously accepted during unwrap (bsc#1227186) - CVE-2024-37371: Fixed invalid memory read when processing message tokens with invalid length fields (bsc#1227187) - CVE-2024-26458: Fixed memory leak at /krb5/src/lib/rpc/pmap_rmt.c (bsc#1220770) - CVE-2024-26461: Fixed memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c (bsc#1220771) - CVE-2024-26462: Fixed memory leak at /krb5/src/kdc/ndr.c (bsc#1220772)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1220770
- https://bugzilla.suse.com/1220771
- https://bugzilla.suse.com/1220772
- https://bugzilla.suse.com/1227186
- https://bugzilla.suse.com/1227187
- https://www.suse.com/security/cve/CVE-2024-26458
- https://www.suse.com/security/cve/CVE-2024-26461
- https://www.suse.com/security/cve/CVE-2024-26462
- https://www.suse.com/security/cve/CVE-2024-37370
- https://www.suse.com/security/cve/CVE-2024-37371
- https://www.suse.com/support/update/announcement/2025/suse-su-202520051-1/