High severity7.1OSV Advisory· Published Jan 16, 2026· Updated Apr 15, 2026
CVE-2025-24528
CVE-2025-24528
Description
In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.
Affected products
1Patches
2969d2be8e235https://github.com/krb5/krb5via osv
78ceba024b64https://github.com/krb5/krb5via osv
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
3News mentions
0No linked articles in our index yet.