CVE-2024-37371

CRITICAL9.1EPSS 2.6%
Published: 6/28/2024Modified: 12/3/2025
Also known as:ALPINE-CVE-2024-37371

Description

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

References (2)