Memory leak in Kerberos 5 - CVE-2024-26462

 

Memory leak in Kerberos 5 - CVE-2024-26462

Published: August 7, 2024


Vulnerability identifier: #VU95441
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-26462
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak in /krb5/src/kdc/ndr.c. A remote attacker can force the application to leak memory and perform denial of service attack.


Affected software

Kerberos 5
Amazon Linux AMI
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Ubuntu
Fedora
IBM Concert Software
IBM Observability with Instana
IBM Automation Decision Services
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
App Connect Enterprise Certified Container
Voice Gateway
Guardium Data Security Center (GDSC)
webMethods Managed File Transfer
IBM Cloud Pak for Watson AIOps
Guardium Data Protection
Robotic Process Automation for Cloud Pak
OpenShift API for Data Protection (OADP)
libgssapi-krb5-2 (Ubuntu package)
krb5-kdc (Ubuntu package)
libkdb5-9 (Ubuntu package)
krb5-admin-server (Ubuntu package)
libgssrpc4 (Ubuntu package)
libkdb5-10 (Ubuntu package)
libkdb5-10t64 (Ubuntu package)
libgssrpc4t64 (Ubuntu package)
krb5 (Red Hat package)
krb5

How to mitigate CVE-2024-26462

Install updates from vendor's website.

Kerberos 5 - update to 1.21.3
IBM Concert Software - update to 1.0.5
Voice Gateway - update to 1.0.8.12
IBM Observability with Instana - update to 1.0.297
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Automation Decision Services - update to 24.0.0.0.4
OpenShift API for Data Protection (OADP) - update to 1.4.2
libgssapi-krb5-2 (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6, 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
krb5-kdc (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6, 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
libkdb5-9 (Ubuntu package) - update to 1.17-6ubuntu4.9
krb5-admin-server (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6, 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
libgssrpc4 (Ubuntu package) - addressed in versions 1.17-6ubuntu4.9, 1.19.2-2ubuntu0.6
libkdb5-10 (Ubuntu package) - update to 1.19.2-2ubuntu0.6
libkdb5-10t64 (Ubuntu package) - addressed in versions 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
libgssrpc4t64 (Ubuntu package) - addressed in versions 1.20.1-6ubuntu2.5, 1.21.3-3ubuntu0.2
krb5 (Red Hat package) - update to 1.21.1-3.el9
krb5 - update to 1.21-3
krb5 - addressed in versions 1.21.3-1.fc39, 1.21.3-1.fc40, 1.21.3-1.fc41
IBM Cloud Pak for Watson AIOps - update to 4.8.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.8
OpenShift Logging - addressed in versions 5.8.17, 5.8.20
Guardium Data Protection - update to 12.0p35
App Connect Enterprise Certified Container - update to 12.8.0
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.20, 23.0.20

External References

Related Security Bulletins