Hi, The following vulnerabilities were published for krb5. CVE-2026-107708[0]: | MIT krb5 through 1.22.2 contains a NULL pointer dereference | vulnerability in the KDC's get_pac_princ_with_realm() that returns | success while leaving the client principal NULL on malformed names. | A malicious or compromised cross-realm trusted KDC can send an | S4U2Proxy request with a PAC carrying a malformed client name to | crash krb5kdc and deny authentication. CVE-2026-107778[1]: | MIT Kerberos 5 (krb5) through 1.22.2 contains a NULL pointer | dereference in make_cred_list() in rd_cred.c that allows | authenticated Kerberos clients to crash services by sending | mismatched KRB-CRED arrays. Attackers can send forwarded credentials | with more tickets than ticket_info entries through | gss_accept_sec_context() to crash GSS-API acceptor services, causing | denial of service. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-107708 https://www.cve.org/CVERecord?id=CVE-2026-107708 https://github.com/krb5/krb5/commit/a88a18cafa1040a0c4f9c8d08288fc98831ec86d [1] https://security-tracker.debian.org/tracker/CVE-2026-107778 https://www.cve.org/CVERecord?id=CVE-2026-107778 https://github.com/krb5/krb5/commit/62196e2b269159a5465f5b8d0ed7cf6f29c3282a Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Salvatore> CVE-2026-107708[0]: | MIT krb5 through 1.22.2 contains a
Salvatore> NULL pointer dereference | vulnerability in the KDC's
Salvatore> get_pac_princ_with_realm() that returns | success while
In the default Debian configuration this is significantly mitigated by
our systemd restart policy: the KDC will restart on such a crash.
Obviously I should fix, but worth noting this has lower impact for
Debian.
Salvatore> CVE-2026-107708[0]: | MIT krb5 through 1.22.2 contains a
Salvatore> NULL pointer dereference | vulnerability in the KDC's
Salvatore> get_pac_princ_with_realm() that returns | success while
In the default Debian configuration this is significantly mitigated by
our systemd restart policy: the KDC will restart on such a crash.
Obviously I should fix, but worth noting this has lower impact for
Debian.