Resource exhaustion in kdcproxy - CVE-2025-59089

 

Resource exhaustion in kdcproxy - CVE-2025-59089

Published: November 19, 2025


Vulnerability identifier: #VU118628
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-59089
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can force the application into connecting to a specially crafted KDC server to trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

kdcproxy
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python-kdcproxy
python-kdcproxy (Red Hat package)
python3-kdcproxy
python3-jwcrypto
custodia
python3-custodia
ipa-healthcheck
ipa-healthcheck-core
slapi-nis
python3-pyusb
python3-yubico
opendnssec
softhsm-devel
softhsm
ipa-server-dns
ipa-client-common
ipa-python-compat
ipa-client
ipa-client-epn
ipa-client-samba
ipa-server
ipa-selinux
ipa-server-trust-ad
ipa-common
python3-ipatests
python3-ipaserver
python3-ipalib
python3-ipaclient
ipa-server-common
python3-qrcode
python3-qrcode-core
bind-dyndb-ldap

How to mitigate CVE-2025-59089

Install updates from vendor's website.

kdcproxy - update to 1.1.0
python-kdcproxy - update to 0.3.2-3
python-kdcproxy (Red Hat package) - addressed in versions 0.3.2-3.el7_9.3, 1.0.0-7.el9_0.1, 1.0.0-7.el9_2.1, 1.0.0-7.el9_4.1, 1.0.0-19.el10_1
python3-kdcproxy - addressed in versions 0.4-5, 1.0.0-4
python3-jwcrypto - update to 0.5.0-2
custodia - update to 0.6.0-3
python3-custodia - update to 0.6.0-3
ipa-healthcheck - update to 0.12-6
ipa-healthcheck-core - update to 0.12-6
slapi-nis - update to 0.60.0-4.0.1
python-kdcproxy - update to 1.0.0-2
python3-kdcproxy - update to 1.0.0-2
python3-pyusb - update to 1.0.0-9.1
python-kdcproxy - addressed in versions 1.1.0-1.fc41, 1.1.0-1.fc42, 1.1.0-1.fc43, 1.1.0-1.fc44
python3-yubico - update to 1.3.2-9.1
opendnssec - update to 2.1.7-2
softhsm-devel - update to 2.6.0-5
softhsm - update to 2.6.0-5
ipa-server-dns - update to 4.9.13-20.0.1
ipa-client-common - update to 4.9.13-20.0.1
ipa-python-compat - update to 4.9.13-20.0.1
ipa-client - update to 4.9.13-20.0.1
ipa-client-epn - update to 4.9.13-20.0.1
ipa-client-samba - update to 4.9.13-20.0.1
ipa-server - update to 4.9.13-20.0.1
ipa-selinux - update to 4.9.13-20.0.1
ipa-server-trust-ad - update to 4.9.13-20.0.1
ipa-common - update to 4.9.13-20.0.1
python3-ipatests - update to 4.9.13-20.0.1
python3-ipaserver - update to 4.9.13-20.0.1
python3-ipalib - update to 4.9.13-20.0.1
python3-ipaclient - update to 4.9.13-20.0.1
ipa-server-common - update to 4.9.13-20.0.1
python3-qrcode - update to 5.3-1
python3-qrcode-core - update to 5.3-1
bind-dyndb-ldap - update to 11.6-6

External References

Related Security Bulletins