MIT krb5(MIT Kerberos 5)是美国麻省理工(Massachusetts Institute Of Technology)大学的一套网络认证协议,它采用客户端/服务器结构,并且客户端和服务器端均可对对方进行身份认证(即双重验证),可防止窃听、防止replay攻击等。 MIT krb5存在数字错误漏洞,该漏洞源于berval2tl_data()函数中整数下溢,未进行边界检查的无符号减法导致后续malloc成功并读取超出缓冲区数据,可能导致堆越界读取。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
| Red Hat | Red Hat Hardened Images | 1.22.2-8.hum1< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Hardened Images | 1.22.2-8.hum1 ~ * |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11774 | 7.6 HIGH | 389-ds-base: 389-ds-base: integer overflow in sasl packet length bypasses size limit leadi |
| CVE-2026-53701 | 6.5 MEDIUM | Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds write in h.266/vvc pps picture parti |
| CVE-2026-53702 | 6.5 MEDIUM | Gstreamer1-plugins-bad-free: gstreamer: stack buffer overflow in h.265 buffering period se |
| CVE-2026-11986 | 4.9 MEDIUM | Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk ro |
No comments yet