#1150461 krb5: CVE-2026-107708 CVE-2026-107778

Package:
src:krb5
Source:
src:krb5
Submitter:
Salvatore Bonaccorso
Date:
2026-10-09 20:39:02 UTC
Severity:
normal
Tags:
#1150461#5
Date:
2026-10-09 19:13:31 UTC
From:
To:
Hi,

The following vulnerabilities were published for krb5.

CVE-2026-107708[0]:
| MIT krb5 through 1.22.2 contains a NULL pointer dereference
| vulnerability in the KDC's get_pac_princ_with_realm() that returns
| success while leaving the client principal NULL on malformed names.
| A malicious or compromised cross-realm trusted KDC can send an
| S4U2Proxy request with a PAC carrying a malformed client name to
| crash krb5kdc and deny authentication.


CVE-2026-107778[1]:
| MIT Kerberos 5 (krb5) through 1.22.2 contains a NULL pointer
| dereference in make_cred_list() in rd_cred.c that allows
| authenticated Kerberos clients to crash services by sending
| mismatched KRB-CRED arrays. Attackers can send forwarded credentials
| with more tickets than ticket_info entries through
| gss_accept_sec_context() to crash GSS-API acceptor services, causing
| denial of service.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-107708
https://www.cve.org/CVERecord?id=CVE-2026-107708
https://github.com/krb5/krb5/commit/a88a18cafa1040a0c4f9c8d08288fc98831ec86d
[1] https://security-tracker.debian.org/tracker/CVE-2026-107778
https://www.cve.org/CVERecord?id=CVE-2026-107778
https://github.com/krb5/krb5/commit/62196e2b269159a5465f5b8d0ed7cf6f29c3282a

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1150461#10
Date:
2026-10-09 20:30:05 UTC
From:
To:

    Salvatore> CVE-2026-107708[0]: | MIT krb5 through 1.22.2 contains a
    Salvatore> NULL pointer dereference | vulnerability in the KDC's
    Salvatore> get_pac_princ_with_realm() that returns | success while


In the default Debian configuration this is significantly mitigated by
our systemd restart policy: the KDC will restart on such a crash.
Obviously I should fix, but worth noting this has lower impact for
Debian.

#1150461#15
Date:
2026-10-09 20:30:05 UTC
From:
To:

    Salvatore> CVE-2026-107708[0]: | MIT krb5 through 1.22.2 contains a
    Salvatore> NULL pointer dereference | vulnerability in the KDC's
    Salvatore> get_pac_princ_with_realm() that returns | success while


In the default Debian configuration this is significantly mitigated by
our systemd restart policy: the KDC will restart on such a crash.
Obviously I should fix, but worth noting this has lower impact for
Debian.