CVE-2025-24528
EUVD-2026-288316.01.2026, 18:16
In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mit | kerberos_5 | 1.7 ≤ 𝑥 < 1.22 | CNA |
Debian Releases