gpp_maybe
Security update for krb5
SUSE-SLE-Micro-Extras-6.0-74
This update for krb5 fixes the following issues: - CVE-2024-37370: Confidential GSS krb5 wrap tokens with invalid plaintext Extra Count fields were erroneously accepted during unwrap (bsc#1227186) - CVE-2024-37371: Fixed invalid memory read when processing message tokens with invalid length fields (bsc#1227187) - CVE-2024-26458: Fixed memory leak at /krb5/src/lib/rpc/pmap_rmt.c (bsc#1220770) - CVE-2024-26461: Fixed memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c (bsc#1220771) - CVE-2024-26462: Fixed memory leak at /krb5/src/kdc/ndr.c (bsc#1220772)
-
Release DateFeb 3 2025
-
ReferencesBugzilla: 1220770, 1220771, 1220772, 1227186, 1227187
CVEs: CVE-2024-26458, CVE-2024-26461, CVE-2024-26462, CVE-2024-37370, CVE-2024-37371 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Micro Extras 6.0 aarch64
-
Packages
SUSE Linux Micro Extras 6.0 s390x
-
Packages
SUSE Linux Micro Extras 6.0 x86_64
-
Packages