Memory leak in Kerberos 5 - CVE-2024-26458

 

Memory leak in Kerberos 5 - CVE-2024-26458

Published: April 9, 2024


Vulnerability identifier: #VU88225
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-26458
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak in /krb5/src/lib/rpc/pmap_rmt.c. A remote attacker can perform a denial of service attack.


Affected software

Kerberos 5
Red Hat OpenShift Container Platform
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Ubuntu
Fedora
IBM Concert Software
Consul
IBM MQ Operator
Splunk User Behavior Analytics (UBA)
IBM Automation Decision Services
Migration Toolkit for Runtimes
Red Hat OpenShift distributed tracing (RHOSDT)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
Dell Secure Connect Gateway
App Connect Enterprise Certified Container
Voice Gateway
DataStax Hyper-Converged Database
Guardium Data Security Center (GDSC)
webMethods Managed File Transfer
PowerStore X
PowerStore T
IBM Cloud Pak for Watson AIOps
Storage Resource Manager
Guardium Data Protection
EMC Cloud Tiering Appliance
Dell Data Protection Central
Robotic Process Automation for Cloud Pak
Juniper Secure Analytics (JSA)
OpenShift API for Data Protection (OADP)
Red Hat OpenShift GitOps
krb5-doc
krb5-plugin-preauth-pkinit
krb5-devel
krb5-debuginfo-32bit
krb5-32bit
krb5-debugsource
krb5-plugin-kdb-ldap
krb5-server
krb5-server-debuginfo
krb5-plugin-preauth-otp-debuginfo
krb5-client
krb5-plugin-preauth-pkinit-debuginfo
krb5-plugin-preauth-otp
krb5-client-debuginfo
krb5-debuginfo
krb5
krb5-plugin-kdb-ldap-debuginfo
libgssrpc4 (Ubuntu package)
libkdb5-9 (Ubuntu package)
libgssapi-krb5-2 (Ubuntu package)
krb5-kdc (Ubuntu package)
krb5-admin-server (Ubuntu package)
krb5-libs
krb5-pkinit
krb5-server-ldap
krb5-workstation
libkadm5
krb5 (Red Hat package)
libkdb5-10 (Ubuntu package)
libkdb5-10t64 (Ubuntu package)
libgssrpc4t64 (Ubuntu package)
krb5-tests
Red Hat OpenShift Serverless
OpenShift Service Mesh
Dell EMC Storage Monitoring and Reporting (SMR)
Red Hat Ceph Storage
IBM Qradar SIEM
Red Hat Single Sign-On
Dell EMC VxRail Appliance
RSA Authentication Manager

How to mitigate CVE-2024-26458

Install update from vendor's website.

Kerberos 5 - update to 1.21.2
IBM Concert Software - update to 1.0.5
Consul - update to 1.20.2
Voice Gateway - update to 1.0.8.12
DataStax Hyper-Converged Database - update to 1.2.5
IBM MQ Operator - addressed in versions 2.0.23, 3.2.0
Guardium Data Security Center (GDSC) - update to 3.6.1
Splunk User Behavior Analytics (UBA) - update to 5.4.3
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Automation Decision Services - update to 24.0.0.0.4
Migration Toolkit for Runtimes - update to 1.2.6
OpenShift API for Data Protection (OADP) - update to 1.4.2
Red Hat OpenShift GitOps - addressed in versions 1.10.6, 1.11.5, 1.12.3
krb5-doc - update to 1.16.3-46.6.1
krb5-plugin-preauth-pkinit - update to 1.16.3-46.6.1
krb5-devel - update to 1.16.3-46.6.1
krb5-debuginfo-32bit - update to 1.16.3-46.6.1
krb5-32bit - update to 1.16.3-46.6.1
krb5-debugsource - update to 1.16.3-46.6.1
krb5-plugin-kdb-ldap - update to 1.16.3-46.6.1
krb5-server - update to 1.16.3-46.6.1
krb5-server-debuginfo - update to 1.16.3-46.6.1
krb5-plugin-preauth-otp-debuginfo - update to 1.16.3-46.6.1
krb5-client - update to 1.16.3-46.6.1
krb5-plugin-preauth-pkinit-debuginfo - update to 1.16.3-46.6.1
krb5-plugin-preauth-otp - update to 1.16.3-46.6.1
krb5-client-debuginfo - update to 1.16.3-46.6.1
krb5-debuginfo - update to 1.16.3-46.6.1
krb5 - update to 1.16.3-46.6.1
krb5-plugin-kdb-ldap-debuginfo - update to 1.16.3-46.6.1
libgssrpc4 (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6
libkdb5-9 (Ubuntu package) - update to 1.17-6ubuntu4.9
libgssapi-krb5-2 (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6, 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
krb5-kdc (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6, 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
krb5-admin-server (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6, 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
krb5-libs - addressed in versions 1.18.2-26.0.2, 1.21.2-3
krb5-pkinit - addressed in versions 1.18.2-26.0.2, 1.21.2-3
krb5-server - addressed in versions 1.18.2-26.0.2, 1.21.2-3
krb5-server-ldap - addressed in versions 1.18.2-26.0.2, 1.21.2-3
krb5-workstation - addressed in versions 1.18.2-26.0.2, 1.21.2-3
krb5-devel - addressed in versions 1.18.2-26.0.2, 1.21.2-3
libkadm5 - addressed in versions 1.18.2-26.0.2, 1.21.2-3
krb5-doc - addressed in versions 1.18.2-26.0.2, 1.21.2-3
krb5 (Red Hat package) - addressed in versions 1.18.2-27.el8_10, 1.21.1-3.el9
libkdb5-10 (Ubuntu package) - update to 1.19.2-2ubuntu0.6
libkdb5-10t64 (Ubuntu package) - addressed in versions 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
libgssrpc4t64 (Ubuntu package) - addressed in versions 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
krb5-tests - update to 1.21.2-3
krb5 - update to 1.21-3
krb5 - addressed in versions 1.21.3-1.fc39, 1.21.3-1.fc40, 1.21.3-1.fc41
Red Hat OpenShift Serverless - update to 1.33.0
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.2
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.2.0
PowerStore X - update to 3.2.1.4-2386214
PowerStore T - update to 4.0.0.2-2365061
IBM Cloud Pak for Watson AIOps - update to 4.8.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.8
Red Hat OpenShift Container Platform - update to 4.12.58
Storage Resource Manager - update to 5.0.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Red Hat Ceph Storage - update to 5.3
OpenShift Logging - addressed in versions 5.8.17, 5.8.20
Dell Secure Connect Gateway - update to 5.24.00.14
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
Red Hat Single Sign-On - update to 7.6.9
Dell EMC VxRail Appliance - update to 8.0.212
RSA Authentication Manager - update to 8.7 SP2 Patch 2
Guardium Data Protection - update to 12.0p35
App Connect Enterprise Certified Container - update to 12.8.0
EMC Cloud Tiering Appliance - update to 13.2.0.2.29
Dell Data Protection Central - update to 19.11.0-2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.20, 23.0.20

External References

Related Security Bulletins