SUSE-SU-2025:20051-1
Dashboard / Vulnerabilities / SUSE-SU-2025:20051-1
SUSE-SU-2025:20051-1
Summary: Security update for krb5
Details: This update for krb5 fixes the following issues: - CVE-2024-37370: Confidential GSS krb5 wrap tokens with invalid plaintext Extra Count fields were erroneously accepted during unwrap (bsc#1227186) - CVE-2024-37371: Fixed invalid memory read when processing message tokens with invalid length fields (bsc#1227187) - CVE-2024-26458: Fixed memory leak at /krb5/src/lib/rpc/pmap_rmt.c (bsc#1220770) - CVE-2024-26461: Fixed memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c (bsc#1220771) - CVE-2024-26462: Fixed memory leak at /krb5/src/kdc/ndr.c (bsc#1220772)
References: https://www.suse.com/support/update/announcement/2025/suse-su-202520051-1/, https://bugzilla.suse.com/1220770, https://bugzilla.suse.com/1220771, https://bugzilla.suse.com/1220772, https://bugzilla.suse.com/1227186, https://bugzilla.suse.com/1227187, https://www.suse.com/security/cve/CVE-2024-26458, https://www.suse.com/security/cve/CVE-2024-26461, https://www.suse.com/security/cve/CVE-2024-26462, https://www.suse.com/security/cve/CVE-2024-37370, https://www.suse.com/security/cve/CVE-2024-37371
Affected packages
Package
Name: krb5
Purl: pkg:rpm/suse/krb5&distro=SUSE%20Linux%20Micro%206.0
Affected ranges
Type: ECOSYSTEM
Events:
