Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-76758

Prevent overflow when calculating ulog block size (CVE-2025-24528) [rhel-10]

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Undefined Undefined
    • rhel-10.0
    • rhel-10.0
    • krb5
    • krb5-1.21.3-7.el10
    • No
    • Moderate
    • 2
    • rhel-idm-ipa
    • ssg_idm
    • 26
    • 2
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • 2025-Q1-Bravo-S2, 2025-Q1-Bravo-S3
    • Release Note Not Required
    • None

      In MIT krb5 release 1.7 and later with incremental propagation enabled, an authenticated attacker can cause kadmind to write beyond the end of the mapped region for the iprop log file, likely causing a process crash.

              jrische@redhat.com Julien Rische
              jrische@redhat.com Julien Rische
              Julien Rische Julien Rische
              Michal Polovka Michal Polovka
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: