Impact
MIT Kerberos 5 up to version 1.22.2 includes a NULL pointer dereference in the get_pac_princ_with_realm() function of the KDC. A malformed client name in the PAC payload can cause the function to return success while leaving the client principal NULL, leading to a crash of the krb5kdc process and denial of authentication services for any user relying on the KDC. The weakness is a classic buffer or pointer error (CWE-476).
Affected Systems
This vulnerability affects the MIT Kerberos 5 package, specifically versions up to and including 1.22.2. Systems running a KDC from this version and any cross‑realm trusted KDCs that may cooperate with it are subject to the risk.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. No EPSS score is available, and the vulnerability is not currently listed in CISA’s KEV catalog. However, an attacker who controls or compromises a cross‑realm trusted KDC can exploit the flaw by sending an S4U2Proxy request with a malformed PAC to crash the krb5kdc, thereby denying service. The attack requires the ability to host or influence a trusted KDC and to send a crafted request, which may limit the threat to environments with cross‑realm or multi‑realm trust relationships, but within those environments the impact is a denial of authentication for all clients of the affected KDC.
OpenCVE Enrichment