NULL Pointer Dereference Vulnerability in MIT krb5 KDC
CVE-2026-107708
6.9MEDIUM
What is CVE-2026-107708?
The MIT krb5 KDC (Key Distribution Center) is susceptible to a vulnerability that occurs when handling malformed names. Specifically, the get_pac_princ_with_realm() function can result in a NULL pointer dereference. A malicious actor with access to a compromised or trusted cross-realm KDC is capable of exploiting this flaw by sending an S4U2Proxy request containing a PAC (Privilege Attribute Certificate) with a faulty client name. This exploit leads to a crash of the krb5kdc service, potentially resulting in denial of authentication for legitimate users.
Affected Version(s)
krb5 0 <= 1.22.2
