Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2024-26461

Published: 29 February 2024

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.

Notes

AuthorNote
Priority reason:
memory leak only unlikely to be triggered
mdeslaur
per upstream: "The k5sealv3.c leak affects an encoding function,
and happens on a bounds check which likely cannot be triggered
with any choice of memory-valid API inputs.  (The bounds check
was itself introduced to quash a different static analysis
defect.)"

Priority

Low

Status

Package Release Status
krb5
Launchpad, Ubuntu, Debian
bionic Needed

focal Needed

jammy Needed

mantic Needed

noble Needed

trusty Needed

upstream Needs triage

xenial Needed