Memory leak in Kerberos 5 - CVE-2024-26461

 

Memory leak in Kerberos 5 - CVE-2024-26461

Published: April 9, 2024 / Updated: August 7, 2024


Vulnerability identifier: #VU88226
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-26461
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak in /krb5/src/lib/gssapi/krb5/k5sealv3.c. A remote attacker can force the application to leak memory and perform denial of service attack.


Affected software

Kerberos 5
Red Hat OpenShift Container Platform
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise High Performance Computing 12
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Ubuntu
Fedora
IBM Concert Software
Splunk User Behavior Analytics (UBA)
IBM Automation Decision Services
Migration Toolkit for Runtimes
Red Hat OpenShift distributed tracing (RHOSDT)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
Dell Secure Connect Gateway
IBM MQ Operator
App Connect Enterprise Certified Container
Voice Gateway
DataStax Hyper-Converged Database
Guardium Data Security Center (GDSC)
webMethods Managed File Transfer
PowerStore X
PowerStore T
IBM Cloud Pak for Watson AIOps
Storage Resource Manager
EMC Cloud Tiering Appliance
Dell Data Protection Central
Robotic Process Automation for Cloud Pak
Juniper Secure Analytics (JSA)
OpenShift API for Data Protection (OADP)
Red Hat OpenShift GitOps
krb5-doc
krb5-plugin-preauth-pkinit
krb5-devel
krb5-debuginfo-32bit
krb5-32bit
krb5-debugsource
krb5-plugin-kdb-ldap
krb5-server
krb5-server-debuginfo
krb5-plugin-preauth-otp-debuginfo
krb5-client
krb5-plugin-preauth-pkinit-debuginfo
krb5-plugin-kdb-ldap-debuginfo
krb5-plugin-preauth-otp
krb5
krb5-debuginfo
krb5-client-debuginfo
krb5-kdc (Ubuntu package)
krb5-admin-server (Ubuntu package)
libgssapi-krb5-2 (Ubuntu package)
libgssrpc4 (Ubuntu package)
libkdb5-9 (Ubuntu package)
krb5-libs
krb5-pkinit
krb5-server-ldap
krb5-workstation
libkadm5
krb5 (Red Hat package)
libkdb5-10 (Ubuntu package)
libkdb5-10t64 (Ubuntu package)
libgssrpc4t64 (Ubuntu package)
krb5-tests
Red Hat OpenShift Serverless
OpenShift Service Mesh
Dell EMC Storage Monitoring and Reporting (SMR)
Red Hat Ceph Storage
IBM Qradar SIEM
Red Hat Single Sign-On
Dell EMC VxRail Appliance
RSA Authentication Manager
IBM CICS TX Advanced

How to mitigate CVE-2024-26461

Install update from vendor's website.

Kerberos 5 - update to 1.21.3
IBM Concert Software - update to 1.0.5
Voice Gateway - update to 1.0.8.12
DataStax Hyper-Converged Database - update to 1.2.5
Guardium Data Security Center (GDSC) - update to 3.6.1
Splunk User Behavior Analytics (UBA) - update to 5.4.3
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Automation Decision Services - update to 24.0.0.0.4
Migration Toolkit for Runtimes - update to 1.2.6
OpenShift API for Data Protection (OADP) - update to 1.4.2
Red Hat OpenShift GitOps - addressed in versions 1.10.6, 1.11.5, 1.12.3
krb5-doc - update to 1.16.3-46.6.1
krb5-plugin-preauth-pkinit - update to 1.16.3-46.6.1
krb5-devel - update to 1.16.3-46.6.1
krb5-debuginfo-32bit - update to 1.16.3-46.6.1
krb5-32bit - update to 1.16.3-46.6.1
krb5-debugsource - update to 1.16.3-46.6.1
krb5-plugin-kdb-ldap - update to 1.16.3-46.6.1
krb5-server - update to 1.16.3-46.6.1
krb5-server-debuginfo - update to 1.16.3-46.6.1
krb5-plugin-preauth-otp-debuginfo - update to 1.16.3-46.6.1
krb5-client - update to 1.16.3-46.6.1
krb5-plugin-preauth-pkinit-debuginfo - update to 1.16.3-46.6.1
krb5-plugin-kdb-ldap-debuginfo - update to 1.16.3-46.6.1
krb5-plugin-preauth-otp - update to 1.16.3-46.6.1
krb5 - update to 1.16.3-46.6.1
krb5-debuginfo - update to 1.16.3-46.6.1
krb5-client-debuginfo - update to 1.16.3-46.6.1
krb5-kdc (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6, 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
krb5-admin-server (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6, 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
libgssapi-krb5-2 (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6, 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
libgssrpc4 (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6
libkdb5-9 (Ubuntu package) - update to 1.17-6ubuntu4.9
krb5-libs - addressed in versions 1.18.2-26.0.2, 1.21.2-3
krb5-pkinit - addressed in versions 1.18.2-26.0.2, 1.21.2-3
krb5-server - addressed in versions 1.18.2-26.0.2, 1.21.2-3
krb5-server-ldap - addressed in versions 1.18.2-26.0.2, 1.21.2-3
krb5-devel - addressed in versions 1.18.2-26.0.2, 1.21.2-3
krb5-workstation - addressed in versions 1.18.2-26.0.2, 1.21.2-3
libkadm5 - addressed in versions 1.18.2-26.0.2, 1.21.2-3
krb5-doc - addressed in versions 1.18.2-26.0.2, 1.21.2-3
krb5 (Red Hat package) - addressed in versions 1.18.2-27.el8_10, 1.21.1-3.el9
libkdb5-10 (Ubuntu package) - update to 1.19.2-2ubuntu0.6
libkdb5-10t64 (Ubuntu package) - addressed in versions 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
libgssrpc4t64 (Ubuntu package) - addressed in versions 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
krb5-tests - update to 1.21.2-3
krb5 - update to 1.21-3
krb5 - addressed in versions 1.21.3-1.fc39, 1.21.3-1.fc40, 1.21.3-1.fc41
Red Hat OpenShift Serverless - update to 1.33.0
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.2
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.2.0
PowerStore X - update to 3.2.1.4-2386214
PowerStore T - update to 4.0.0.2-2365061
IBM Cloud Pak for Watson AIOps - update to 4.8.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.8
Red Hat OpenShift Container Platform - update to 4.12.58
Storage Resource Manager - update to 5.0.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Red Hat Ceph Storage - update to 5.3
OpenShift Logging - addressed in versions 5.8.17, 5.8.20
Dell Secure Connect Gateway - update to 5.24.00.14
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
Red Hat Single Sign-On - update to 7.6.9
Dell EMC VxRail Appliance - update to 8.0.212
RSA Authentication Manager - update to 8.7 SP2 Patch 2
IBM MQ Operator - addressed in versions 9.3.0.20-r2, 9.4.0.0-r3
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
App Connect Enterprise Certified Container - update to 12.8.0
EMC Cloud Tiering Appliance - update to 13.2.0.2.29
Dell Data Protection Central - update to 19.11.0-2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.20, 23.0.20

External References

Related Security Bulletins