VYPR

rpm package

opensuse/krb5&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/krb5&distro=openSUSE%20Leap%2016.0

Vulnerabilities (3)

  • CVE-2026-11850MedJun 11, 2026
    affected < 1.21.3-160000.4.1fixed 1.21.3-160000.4.1

    An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a

  • CVE-2026-40356MedApr 28, 2026
    affected < 1.21.3-160000.3.1fixed 1.21.3-160000.3.1

    In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possib

  • CVE-2026-40355MedApr 28, 2026
    affected < 1.21.3-160000.3.1fixed 1.21.3-160000.3.1

    In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate