First published: Mon Feb 26 2024(Updated: )
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/krb5 | <=1.18.3-6+deb11u5<=1.18.3-6+deb11u6<=1.20.1-2+deb12u2<=1.21.3-4 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Software Stack | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Virtual Appliance | <=ISVG 10.0.2 | |
IBM Security Verify Governance Identity Manager Container | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-26458 has been categorized with a medium severity level due to the nature of the memory leak.
To fix CVE-2024-26458, update to the latest version of Kerberos 5 that addresses this memory leak.
CVE-2024-26458 affects IBM MQ Operator and supplied MQ Advanced container images within specific version ranges.
The impact of CVE-2024-26458 includes memory leaks that could lead to reduced performance or crashes over time.
As of the latest information, there are no confirmed reports of active exploitation for CVE-2024-26458.