CVE-2025-24528

HIGH

MIT Kerberos <1.22 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.

Scores

CVSS v3 7.1
EPSS 0.0021
EPSS Percentile 42.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-190
Status published
Products (1)
MIT/Kerberos 5 1.7 - 1.22
Published Jan 16, 2026
Tracked Since Feb 18, 2026