Impact
A flaw in the Linux kernel’s Kerberos (krb5) cryptographic subsystem causes freshly derived key buffers to be freed with a generic kfree() call. Because the kernel does not zero out the memory before deallocating it, the raw key material remains intact in the freed slab object. If an attacker can read kernel memory after the buffer is freed, the sensitive cryptographic keys could be recovered, potentially allowing cryptographic operations to be bypassed or decrypted. This vulnerability directly leads to exposure of confidential information that is not supposed to be recoverable after use. The weakness is a classic misuse of memory deallocation for sensitive data, representing a serious security defect in the kernel’s handling of key material.
Affected Systems
The issue affects the Linux kernel across all supported distributions. Any system running a kernel version that implements the krb5 prepare encryption and checksum functions without the official patch is vulnerable. The problem applies universally, regardless of the specific distribution name, as the underlying kernel code is identical.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity impact. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet. The likely attack vector is a local or privilege‑escalated attacker with access to read kernel memory after the buffer is freed, possibly through another kernel vulnerability or misconfigured privileged service. The impact depends on the attacker’s ability to read the freed slab, which is a non‑trivial loopback scenario but still a severe risk for systems running sensitive Kerberos services.
OpenCVE Enrichment