NULL pointer dereference in Kerberos 5 - CVE-2021-37750

 

NULL pointer dereference in Kerberos 5 - CVE-2021-37750

Published: September 22, 2021 / Updated: March 15, 2022


Vulnerability identifier: #VU56828
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37750
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in the Key Distribution Center (KDC) in kdc/do_tgs_req.c. A remote user can pass specially crafted data via the FAST inner body that lacks a server field, trigger a NULL pointer dereference error and perform a denial of service (DoS) attack.


Affected software

Kerberos 5
Gentoo Linux
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
PowerSC
SUSE MicroOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
CentOS
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Server Applications
Ubuntu
openEuler
Fedora
Service Telemetry Framework
Red Hat Advanced Cluster Management for Kubernetes
Isolation Segment
VMware Tanzu Application Service for VMs
Session Smart Router
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
krb5 (Red Hat package)
krb5-plugin-preauth-pkinit-debuginfo
krb5-client-debuginfo
krb5-debuginfo
krb5-debugsource
krb5-devel
krb5-plugin-kdb-ldap
krb5-plugin-kdb-ldap-debuginfo
krb5-plugin-preauth-otp
krb5-plugin-preauth-otp-debuginfo
krb5-plugin-preauth-pkinit
krb5-server
krb5-server-debuginfo
krb5-client
krb5-32bit
krb5-32bit-debuginfo
krb5
krb5-pkinit (Ubuntu package)
krb5-kdc (Ubuntu package)
krb5-k5tls (Ubuntu package)
krb5-kdc-ldap (Ubuntu package)
krb5-debuginfo-32bit
krb5-doc
krb5-help
krb5-libs
krb5-pkinit
krb5-server-ldap
krb5-workstation
libkadm5
app-crypt/mit-krb5
Oracle Communications Cloud Native Core Network Slice Selection Function
IBM Watson Machine Learning Accelerator
Platform Automation Toolkit
Dell PowerProtect Cyber Recovery
OpenShift Virtualization
Juniper Junos Space

How to mitigate CVE-2021-37750

Install update from vendor's website.

Kerberos 5 - update to 1.19.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.1.11, 2.1.12, 2.2.10, 2.3.3
krb5 (Red Hat package) - addressed in versions 1.15.1-51.el7_9, 1.18.2-8.3.el8_4
krb5-plugin-preauth-pkinit-debuginfo - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-client-debuginfo - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-debuginfo - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-debugsource - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-devel - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-plugin-kdb-ldap - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-plugin-kdb-ldap-debuginfo - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-plugin-preauth-otp - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-plugin-preauth-otp-debuginfo - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-plugin-preauth-pkinit - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-server - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-server-debuginfo - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-client - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-32bit - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-32bit-debuginfo - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1
krb5 - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-3.24.1, 1.16.3-46.12.1
krb5-pkinit (Ubuntu package) - addressed in versions 1.16-2ubuntu0.4, 1.17-6ubuntu4.3
krb5-kdc (Ubuntu package) - addressed in versions 1.16-2ubuntu0.4, 1.17-6ubuntu4.3
krb5-k5tls (Ubuntu package) - addressed in versions 1.16-2ubuntu0.4, 1.17-6ubuntu4.3
krb5-kdc-ldap (Ubuntu package) - addressed in versions 1.16-2ubuntu0.4, 1.17-6ubuntu4.3
krb5-debuginfo-32bit - update to 1.16.3-46.12.1
krb5-doc - update to 1.16.3-46.12.1
krb5-help - update to 1.18.2-5
krb5-libs - update to 1.18.2-5
krb5-client - update to 1.18.2-5
krb5 - update to 1.18.2-5
krb5-debugsource - update to 1.18.2-5
krb5-server - update to 1.18.2-5
krb5-debuginfo - update to 1.18.2-5
krb5-devel - update to 1.18.2-5
krb5-libs - update to 1.18.2-8.3
krb5-pkinit - update to 1.18.2-8.3
krb5-server - update to 1.18.2-8.3
krb5-server-ldap - update to 1.18.2-8.3
krb5-workstation - update to 1.18.2-8.3
libkadm5 - update to 1.18.2-8.3
krb5-devel - update to 1.18.2-8.3
krb5 - addressed in versions 1.18.2-31.fc33, 1.19.2-2.fc34
app-crypt/mit-krb5 - update to 1.21.2
IBM Watson Machine Learning Accelerator - update to 2.3.9
OpenShift Virtualization - addressed in versions 2.6.8, 4.9.0
Isolation Segment - addressed in versions 2.11.31, 2.13.16, 3.0.9, 4.0.0
VMware Tanzu Application Service for VMs - addressed in versions 2.11.37, 2.13.19, 3.0.9, 4.0.0
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.1
Session Smart Router - addressed in versions 5.4.7, 5.5.3
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
Juniper Junos Space - update to 22.1R1

External References

Related Security Bulletins