Release date:
2026-09-17 11:42:24 UTC
Description:
- CVE-2018-5709: bounds-check key and name counts when loading a KDB dump
- CVE-2020-28196: add recursion limit for ASN.1 indefinite lengths
- CVE-2021-36222: fix KDC null deref on bad encrypted challenge
- CVE-2022-42898: fix integer overflows in PAC parsing
- CVE-2024-37370: verify the Extra Count field of CFX wrap tokens
- CVE-2024-37371: reject GSS message tokens with invalid length fields
- Bound dbentry->e_length when loading a KDB dump (upstream a9654198); the
last unguarded 32-to-16-bit assignment in the function CVE-2018-5709
bounds
- Validate the PAC length in mspac_internalize() (upstream 63ae6a8d); the
serialized length reaching krb5_pac_parse() was unchecked. Adds the internal
helper k5_ser_unpack_len to libkrb5.exports, as upstream does; no public
interface changes
- Carry the t_invalid.c regression tests from upstream 55fbf435, split across
the CVE-2024-37370 and CVE-2024-37371 patches to match the code split.
test_cfx_altered_ec is the case that fails without the 37370 fix and
test_cfx_large_ec the one that fails without the 37371 fix; the other two
carried cases do not discriminate on 1.17 and are noted as such in the
patch headers. Test-only: no shipped binary changes
Updated packages:
-
alt-krb5-devel-1.17-14.el8.x86_64.rpm
sha:1de27b7f04b27c830dd750ace9a2fc8c76ff44e9e9ff24e3e5eef1dcd9eefe6d
-
alt-krb5-libs-1.17-14.el8.x86_64.rpm
sha:a1b38049e235ca95954a4e3803eec7524bf58d9e186f83469e595caf38658ec4
-
alt-krb5-pkinit-1.17-14.el8.x86_64.rpm
sha:d50c5c8ad29ba095e157ea9b323bec6c3d4e670eb38b0281d75e3e7f3ebd3a90
-
alt-krb5-server-1.17-14.el8.x86_64.rpm
sha:7bd2021cb38d0dc8ecd0592bca575572bc64373af1216245254161d34eeaf87c
-
alt-krb5-server-ldap-1.17-14.el8.x86_64.rpm
sha:1b13cc7c2e48e5ee0e6060f00f56dd50bd1cf9bda8b3f6acc3c44a1aa55ff5b2
-
alt-krb5-workstation-1.17-14.el8.x86_64.rpm
sha:744397312a5235ae618d5bde2db8ad7461a7dbf32777514d8a548db3ac77d3ab
-
alt-libkadm5-1.17-14.el8.x86_64.rpm
sha:9bf48ad579a2b2feb9043895c2c24b194eef9ccd62c6470943a8beb62c5b1974
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.