Description
MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a malformed client name to crash krb5kdc and deny authentication.
Published: 2026-10-08
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via KDC crash
Action: Apply Patch
AI Analysis

Impact

MIT Kerberos 5 up to version 1.22.2 includes a NULL pointer dereference in the get_pac_princ_with_realm() function of the KDC. A malformed client name in the PAC payload can cause the function to return success while leaving the client principal NULL, leading to a crash of the krb5kdc process and denial of authentication services for any user relying on the KDC. The weakness is a classic buffer or pointer error (CWE-476).

Affected Systems

This vulnerability affects the MIT Kerberos 5 package, specifically versions up to and including 1.22.2. Systems running a KDC from this version and any cross‑realm trusted KDCs that may cooperate with it are subject to the risk.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. No EPSS score is available, and the vulnerability is not currently listed in CISA’s KEV catalog. However, an attacker who controls or compromises a cross‑realm trusted KDC can exploit the flaw by sending an S4U2Proxy request with a malformed PAC to crash the krb5kdc, thereby denying service. The attack requires the ability to host or influence a trusted KDC and to send a crafted request, which may limit the threat to environments with cross‑realm or multi‑realm trust relationships, but within those environments the impact is a denial of authentication for all clients of the affected KDC.

Generated by OpenCVE AI on October 8, 2026 at 21:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MIT Kerberos installation to version 1.22.3 or later to apply the vendor‑issued patch for the NULL pointer dereference.
  • Restrict the configuration of cross‑realm delegation and ensure that only trusted KDCs are authorized to process S4U2Proxy requests, reducing the attack surface.
  • Continuously monitor krb5kdc logs for unexpected crashes or authentication failures and apply updates promptly to maintain service availability.

Generated by OpenCVE AI on October 8, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a malformed client name to crash krb5kdc and deny authentication.
Title MIT krb5 through 1.22.2 KDC NULL Pointer Dereference via S4U2Proxy PAC
First Time appeared Mit
Mit kerberos 5
Weaknesses CWE-476
CPEs cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*
Vendors & Products Mit
Mit kerberos 5
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T20:15:53.534Z

Reserved: 2026-10-08T16:52:24.550Z

Link: CVE-2026-107708

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T21:17:52.223

Modified: 2026-10-08T21:33:42.423

Link: CVE-2026-107708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T22:00:17Z

Weaknesses