CVE-2021-36222: Null Pointer Dereference
Published Jul 21, 2021
·Updated
ecverify in kdc/kdcpreauthec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation.
Affected Software
11 affected componentsFixes available
debian/krb5<=1.17-3+deb10u1, <=1.17-3, <=1.18.3-5
1.18.3-61.17-3+deb10u2
debian/krb5
1.17-3+deb10u41.17-3+deb10u51.18.3-6+deb11u41.18.3-6+deb11u31.20.1-2+deb12u11.20.1-4
MIT Kerberos 5<1.18.4
MIT Kerberos 5>=1.19.0<1.19.2
Debian Debian Linux=10.0
NetApp Active Iq Unified Manager Vmware Vsphere
NetApp Active Iq Unified Manager Windows
NetApp OnCommand Insight
NetApp OnCommand Workflow Automation
NetApp Snapcenter
Oracle MySQL Server>=8.0.0<=8.0.26
Remediation
Patch Available
Event History
Jul 22, 2021
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-36222.
2
What is the severity of CVE-2021-36222?
The severity of CVE-2021-36222 is high with a severity value of 7.5.
3
Which software is affected by CVE-2021-36222?
MIT Kerberos 5 before 1.18.4 and 1.19.x before 1.19.2 are affected by CVE-2021-36222.
4
How can remote attackers exploit CVE-2021-36222?
Remote attackers can exploit CVE-2021-36222 to cause a NULL pointer dereference and daemon crash.
5
Where can I find more information about CVE-2021-36222?
You can find more information about CVE-2021-36222 on the MIT Kerberos 5 GitHub page and the NetApp security advisory page.