Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Oracle Linux 9 ELSA-2024-6166 Moderate: krb5 DoS Security Issue

oracle
Calendar Grey September 4, 2024
Scroller Oracle
The Oracle Linux Security Advisory ELSA-2024-6166 addresses vulnerabilities in the krb5 packages, particularly focusing on rectifying issues related to GSS message token management.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Summary

[1.21.1-2.0.1] - Fixed race condition in krb5_set_password() [Orabug: 33609767] [1.21.1-2] - CVE-2024-37370 CVE-2024-37371 Fix vulnerabilities in GSS message token handling Resolves: RHEL-45401 RHEL-45390

SRPMs

http://oss.oracle.com/ol9/SRPMS-updates//krb5-1.21.1-2.0.1.el9_4.src.rpm

x86_64

krb5-devel-1.21.1-2.0.1.el9_4.i686.rpm krb5-devel-1.21.1-2.0.1.el9_4.x86_64.rpm krb5-libs-1.21.1-2.0.1.el9_4.i686.rpm krb5-libs-1.21.1-2.0.1.el9_4.x86_64.rpm krb5-pkinit-1.21.1-2.0.1.el9_4.i686.rpm krb5-pkinit-1.21.1-2.0.1.el9_4.x86_64.rpm krb5-server-1.21.1-2.0.1.el9_4.i686.rpm krb5-server-1.21.1-2.0.1.el9_4.x86_64.rpm krb5-server-ldap-1.21.1-2.0.1.el9_4.i686.rpm krb5-server-ldap-1.21.1-2.0.1.el9_4.x86_64.rpm krb5-workstation-1.21.1-2.0.1.el9_4.x86_64.rpm libkadm5-1.21.1-2.0.1.el9_4.i686.rpm libkadm5-1.21.1-2.0.1.el9_4.x86_64.rpm

aarch64

krb5-devel-1.21.1-2.0.1.el9_4.aarch64.rpm krb5-libs-1.21.1-2.0.1.el9_4.aarch64.rpm krb5-pkinit-1.21.1-2.0.1.el9_4.aarch64.rpm krb5-server-1.21.1-2.0.1.el9_4.aarch64.rpm krb5-server-ldap-1.21.1-2.0.1.el9_4.aarch64.rpm krb5-workstation-1.21.1-2.0.1.el9_4.aarch64.rpm libkadm5-1.21.1-2.0.1.el9_4.aarch64.rpm

Related CVEs: CVE-2024-37370 CVE-2024-37371

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.