CVE Vulnerabilities

CVE-2023-39975

Double Free

Published: Aug 16, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.8 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Kerberos_5 Mit 1.21 (including) 1.21.2 (excluding)
Red Hat Enterprise Linux 9 RedHat krb5-0:1.21.1-1.el9 *
Red Hat Enterprise Linux 9 RedHat krb5-0:1.21.1-1.el9 *
Krb5 Ubuntu bionic *
Krb5 Ubuntu trusty *
Krb5 Ubuntu xenial *

Potential Mitigations

References