Integer Overflow Vulnerability in MIT Kerberos 5 Releases
CVE-2025-24528
7.1HIGH
What is CVE-2025-24528?
An integer overflow vulnerability exists in MIT Kerberos 5 prior to version 1.22, particularly within the resize() function of kdb_log.c. An authenticated attacker can exploit this flaw by supplying a large update size, leading to an out-of-bounds write operation, which may result in a crash of the kadmind daemon. The vulnerability poses a risk of denial of service and could potentially allow for further exploitation if not addressed.
Affected Version(s)
Kerberos 5 1.7 < 1.22
