Out-of-bounds write in Kerberos 5 - CVE-2025-24528

 

Out-of-bounds write in Kerberos 5 - CVE-2025-24528

Published: February 3, 2025


Vulnerability identifier: #VU103504
CSH Severity: Medium
CVSS v4 BT: 4.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-24528
CWE-ID: CWE-787
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when calculating ulog block size in kadmind. A remote user can trigger an out-of-bounds write and perform a denial of service (DoS) attack.


Affected software

Kerberos 5
Red Hat OpenShift Container Platform
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Observability with Instana
Netcool Operations Insight
Submariner
Service Interconnect
Multicluster GlobalHub
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
APEX Cloud Platform for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
IBM TXSeries for Multiplatforms
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Basesystem Module
Server Applications Module
openSUSE Leap
openEuler
Ubuntu
Fedora
Guardium Data Security Center (GDSC)
APEX Cloud Platform for Microsoft Azure
SmartFabric OS10
IBM Qradar SIEM
IBM API Connect
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Service Mesh
SmartFabric Manager
OpenShift API for Data Protection (OADP)
krb5 (Red Hat package)
krb5-workstation
krb5-devel
krb5-libs
krb5-pkinit
krb5-server
krb5-server-ldap
libkadm5
libgssapi-krb5-2 (Ubuntu package)
krb5-kdc (Ubuntu package)
libgssrpc4 (Ubuntu package)
krb5-admin-server (Ubuntu package)
libkdb5-9 (Ubuntu package)
krb5-doc
libkdb5-10 (Ubuntu package)
krb5-client
krb5
krb5-debuginfo
krb5-debugsource
krb5-help
krb5-plugin-preauth-pkinit-debuginfo
krb5-mini-devel
krb5-plugin-preauth-otp
krb5-plugin-preauth-spake
krb5-plugin-kdb-ldap
krb5-mini-debuginfo
krb5-plugin-preauth-otp-debuginfo
krb5-server-debuginfo
krb5-plugin-preauth-spake-debuginfo
krb5-32bit-debuginfo
krb5-devel-32bit
krb5-32bit
krb5-devel-64bit
krb5-64bit-debuginfo
krb5-64bit
krb5-plugin-kdb-ldap-debuginfo
krb5-mini
krb5-client-debuginfo
krb5-plugin-preauth-pkinit
krb5-mini-debugsource
libgssrpc4t64 (Ubuntu package)
libkdb5-10t64 (Ubuntu package)
krb5-tests
crypto-policies-scripts
crypto-policies
Red Hat OpenShift GitOps
Red Hat Ceph Storage
IBM CICS TX Advanced
IBM App Connect Enterprise

How to mitigate CVE-2025-24528

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.1
IBM Observability with Instana - update to 1.0.298
Netcool Operations Insight - update to 1.6.15
Guardium Data Security Center (GDSC) - update to 3.8.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 12 IF02
IBM API Connect - update to 10.0.8.5
Submariner - update to 0.20.1
Red Hat OpenShift Serverless - update to 1
SmartFabric Manager - update to 1.3.0
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.7, 1.4.5
Service Interconnect - update to 1.4
Multicluster GlobalHub - update to 1.4.1
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
krb5 (Red Hat package) - addressed in versions 1.15.1-55.el7_9.4, 1.18.2-31.el8_10
krb5-workstation - addressed in versions 1.15.1-55.0.2, 1.18.2-31.0.1, 1.21.2-5
krb5-devel - addressed in versions 1.15.1-55.0.2, 1.18.2-31.0.1, 1.21.2-5
krb5-libs - addressed in versions 1.15.1-55.0.2, 1.18.2-31.0.1, 1.21.2-5
krb5-pkinit - addressed in versions 1.15.1-55.0.2, 1.18.2-31.0.1, 1.21.2-5
krb5-server - addressed in versions 1.15.1-55.0.2, 1.18.2-31.0.1, 1.21.2-5
krb5-server-ldap - addressed in versions 1.15.1-55.0.2, 1.18.2-31.0.1, 1.21.2-5
libkadm5 - addressed in versions 1.15.1-55.0.2, 1.18.2-31.0.1, 1.21.2-5
Red Hat OpenShift GitOps - addressed in versions 1.15.3, 1.16.1
libgssapi-krb5-2 (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6, 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
krb5-kdc (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6, 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
libgssrpc4 (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6
krb5-admin-server (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6, 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
libkdb5-9 (Ubuntu package) - update to 1.17-6ubuntu4.9
krb5-doc - addressed in versions 1.18.2-31.0.1, 1.21.2-5
libkdb5-10 (Ubuntu package) - update to 1.19.2-2ubuntu0.6
krb5-client - update to 1.19.2-23
krb5 - update to 1.19.2-23
krb5-debuginfo - update to 1.19.2-23
krb5-devel - update to 1.19.2-23
krb5-debugsource - update to 1.19.2-23
krb5-libs - update to 1.19.2-23
krb5-server - update to 1.19.2-23
krb5-help - update to 1.19.2-23
krb5-server - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-plugin-preauth-pkinit-debuginfo - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-client - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5 - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-debugsource - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-mini-devel - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-plugin-preauth-otp - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-plugin-preauth-spake - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-plugin-kdb-ldap - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-mini-debuginfo - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-plugin-preauth-otp-debuginfo - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-server-debuginfo - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-plugin-preauth-spake-debuginfo - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-32bit-debuginfo - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-devel-32bit - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-32bit - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-devel-64bit - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-64bit-debuginfo - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-64bit - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-plugin-kdb-ldap-debuginfo - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-mini - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-devel - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-client-debuginfo - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-debuginfo - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-plugin-preauth-pkinit - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
krb5-mini-debugsource - addressed in versions 1.19.2-150300.22.1, 1.19.2-150400.3.15.1, 1.20.1-150500.3.12.1, 1.20.1-150600.11.8.1
libgssrpc4t64 (Ubuntu package) - addressed in versions 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
libkdb5-10t64 (Ubuntu package) - addressed in versions 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
krb5-tests - update to 1.21.2-5
krb5 - addressed in versions 1.21.3-3.fc40, 1.21.3-4.fc41
Ansible Automation Platform - addressed in versions 2.4, 2.5
Multicluster Engine for Kubernetes - addressed in versions 2.4.9, 2.5.9, 2.6.7
OpenShift Service Mesh - update to 2.5.10
Red Hat Advanced Cluster Management for Kubernetes - update to 2.13.3
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
Red Hat OpenShift Dev Spaces - update to 3.21.0
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.5.8, 4.6.4, 4.7.1
Red Hat OpenShift Container Platform - addressed in versions 4.13.57, 4.14.50
Red Hat Ceph Storage - update to 8.1
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
SmartFabric OS10 - addressed in versions 10.5.4.15, 10.5.5.14, 10.5.6.9
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix4
IBM App Connect Enterprise - addressed in versions 12.0.13, 12.13.0
crypto-policies-scripts - update to 20230920.570ea89-150600.3.3.1
crypto-policies - update to 20230920.570ea89-150600.3.3.1

External References

Related Security Bulletins