CVE-2025-24528

ADVISORY - ubuntu

Summary

In MIT krb5 release 1.7 and later with incremental propagation enabled, an authenticated attacker can cause kadmind to write beyond the end of the mapped region for the iprop log file, likely causing a process crash.

Common Weakness Enumeration (CWE)


Ubuntu

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium
PackageTypeOS NameOS VersionAffected RangesFix Versions
ubuntu/krb5debubuntu22.04<1.19.2-2ubuntu0.61.19.2-2ubuntu0.6
ubuntu/krb5debubuntu24.04<1.20.1-6ubuntu2.51.20.1-6ubuntu2.5
ubuntu/krb5debubuntu25.04<1.21.3-4ubuntu21.21.3-4ubuntu2
ubuntu/krb5debubuntu24.10<1.21.3-3ubuntu0.21.21.3-3ubuntu0.2
ubuntu/krb5debubuntu20.04<1.17-6ubuntu4.91.17-6ubuntu4.9

Severity and metrics

No CVSS data available from this advisory.

Debian

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

Alma

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

Rocky

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow

Oracle

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

Oracle

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium