CVE-2024-37371

CRITICAL

MIT Kerberos 5 < 1.21.3 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.

Scores

CVSS v3 9.1
EPSS 0.0261
EPSS Percentile 85.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (3)
debian/debian_linux 11.0
debian/debian_linux 12.0
mit/kerberos_5 < 1.21.3
Published Jun 28, 2024
Tracked Since Feb 18, 2026