CVE-2024-37371

CRITICAL

MIT Kerberos 5 < 1.21.3 - Out-of-bounds Read via GSS Message Token Length Field

Title source: llm
STIX 2.1

Description

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.

Scores

CVSS v3 9.1
EPSS 0.0186
EPSS Percentile 76.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (3)
debian/debian_linux 11.0
debian/debian_linux 12.0
mit/kerberos_5 < 1.21.3
Published Jun 28, 2024
Tracked Since Feb 18, 2026