In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.
History

Fri, 16 Jan 2026 19:30:00 +0000

Type Values Removed Values Added
References

Fri, 16 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 17:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in krb5. With incremental propagation enabled, an authenticated attacker can cause kadmind to write beyond the end of the mapped region for the iprop log file. This issue can trigger a process crash and lead to a denial of service. In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.
First Time appeared Mit
Mit kerberos 5
Weaknesses CWE-190
CPEs cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*
Vendors & Products Mit
Mit kerberos 5
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H'}


Tue, 03 Jun 2025 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat discovery
CPEs cpe:/a:redhat:discovery:1.14::el9
Vendors & Products Redhat discovery

Wed, 14 May 2025 02:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:9
cpe:/o:redhat:enterprise_linux:9

Fri, 14 Mar 2025 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat enterprise Linux
Redhat openshift Distributed Tracing
CPEs cpe:/a:redhat:openshift_distributed_tracing:3.5::el8
cpe:/o:redhat:enterprise_linux:8
Vendors & Products Redhat enterprise Linux
Redhat openshift Distributed Tracing

Thu, 13 Feb 2025 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat rhel Els
CPEs cpe:/o:redhat:rhel_els:7
Vendors & Products Redhat
Redhat rhel Els

Thu, 13 Feb 2025 01:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in krb5. With incremental propagation enabled, an authenticated attacker can cause kadmind to write beyond the end of the mapped region for the iprop log file. This issue can trigger a process crash and lead to a denial of service.
Title krb5: overflow when calculating ulog block size
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-01-16T00:00:00.000Z

Updated: 2026-01-16T18:06:59.339Z

Reserved: 2025-01-23T00:00:00.000Z

Link: CVE-2025-24528

cve-icon Vulnrichment

Updated: 2026-01-16T18:06:59.339Z

cve-icon NVD

Status : Received

Published: 2026-01-16T18:16:06.633

Modified: 2026-01-16T19:16:17.213

Link: CVE-2025-24528

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-01-28T00:00:00Z

Links: CVE-2025-24528 - Bugzilla