USN-6947-1: Kerberos vulnerabilities
It was discovered that Kerberos incorrectly handled GSS message tokens where an unwrapped token could appear to be truncated. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-37370) It was discovered that Kerberos incorrectly handled GSS message tokens when sent a token with invalid length fields. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-37371)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6947-1?
The severity of USN-6947-1 is classified as a potential denial-of-service vulnerability due to improper handling of GSS message tokens in Kerberos.
How do I fix USN-6947-1?
To fix USN-6947-1, you should upgrade to the patched version of the affected packages, specifically 1.20.1-6ubuntu2.1 or a later version for Ubuntu 24.04.
Which packages are affected by USN-6947-1?
The affected packages for USN-6947-1 include krb5-admin-server, krb5-kdc, krb5-user, and various libkrb5 and libgssapi libraries.
What systems are affected by USN-6947-1?
USN-6947-1 affects Ubuntu versions 24.04 and 22.04 based on the specific package versions listed.
What should I do if I can't update for USN-6947-1?
If you cannot update due to compatibility issues, consider implementing temporary network segmentation to mitigate risk until an update can be applied.