MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a malformed client name to crash krb5kdc and deny authentication.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a malformed client name to crash krb5kdc and deny authentication. | |
| Title | MIT krb5 through 1.22.2 KDC NULL Pointer Dereference via S4U2Proxy PAC | |
| First Time appeared |
Mit
Mit kerberos 5 |
|
| Weaknesses | CWE-476 | |
| CPEs | cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mit
Mit kerberos 5 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T20:15:53.534Z
Reserved: 2026-10-08T16:52:24.550Z
Link: CVE-2026-107708
No data.
Status : Awaiting Analysis
Published: 2026-10-08T21:17:52.223
Modified: 2026-10-08T21:33:42.423
Link: CVE-2026-107708
No data.
OpenCVE Enrichment
Updated: 2026-10-08T21:30:18Z
Weaknesses