Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a malformed client name to crash krb5kdc and deny authentication. | |
| Title | MIT krb5 through 1.22.2 KDC NULL Pointer Dereference via S4U2Proxy PAC | |
| First Time appeared |
Mit
Mit kerberos 5 |
|
| Weaknesses | CWE-476 | |
| CPEs | cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mit
Mit kerberos 5 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T20:15:53.534Z
Reserved: 2026-10-08T16:52:24.550Z
Link: CVE-2026-107708
No data.
Status : Awaiting Analysis
Published: 2026-10-08T21:17:52.223
Modified: 2026-10-08T21:33:42.423
Link: CVE-2026-107708
No data.
OpenCVE Enrichment
Updated: 2026-10-08T21:30:18Z