NULL Pointer Dereference Vulnerability in MIT krb5 KDC
CVE-2026-107708

6.9MEDIUM

Key Information:

Vendor

Mit

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107708?

The MIT krb5 KDC (Key Distribution Center) is susceptible to a vulnerability that occurs when handling malformed names. Specifically, the get_pac_princ_with_realm() function can result in a NULL pointer dereference. A malicious actor with access to a compromised or trusted cross-realm KDC is capable of exploiting this flaw by sending an S4U2Proxy request containing a PAC (Privilege Attribute Certificate) with a faulty client name. This exploit leads to a crash of the krb5kdc service, potentially resulting in denial of authentication for legitimate users.

Affected Version(s)

krb5 0 <= 1.22.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani
.