RHSA-2024:3268: Low: krb5 security update
Kerberos is a network authentication system, which can improve the security of your network by eliminating the insecure practice of sending passwords over the network in unencrypted form. It allows clients and servers to authenticate to each other with the help of a trusted third party, the Kerberos key distribution center (KDC).Security Fix(es): krb5: Memory leak at /krb5/src/lib/rpc/pmaprmt.c (CVE-2024-26458) krb5: Memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c (CVE-2024-26461) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What vulnerabilities does RHSA-2024:3268 address?
RHSA-2024:3268 addresses vulnerabilities in the Kerberos network authentication system affecting multiple Red Hat Enterprise Linux packages.
What is the severity level of RHSA-2024:3268?
The severity level of RHSA-2024:3268 is high, indicating potential impacts on system security.
How can I remediate RHSA-2024:3268?
To remediate RHSA-2024:3268, update the affected packages to version 1.18.2-27.el8_10 or higher.
Which Red Hat Enterprise Linux versions are affected by RHSA-2024:3268?
Red Hat Enterprise Linux versions including x86_64, ARM 64, Power little endian, and IBM z Systems are affected by RHSA-2024:3268.
Are there specific packages mentioned in RHSA-2024:3268?
Yes, the impacted packages include krb5, krb5-devel, krb5-libs, and krb5-server among others.