Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2024-26462

Published: 29 February 2024

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.

Notes

AuthorNote
mdeslaur
per upstream: "The ndr.c leak also affects an encoding function,
and triggers if the input contains invalid UTF-8.  This one
might be triggerable by a request (though it may require
elevated privilege), but I would not have requested a CVE for
it myself."

Priority

Medium

Status

Package Release Status
krb5
Launchpad, Ubuntu, Debian
bionic Needed

focal Needed

jammy Needed

mantic Needed

noble Needed

trusty Needed

upstream Needs triage

xenial Needed