Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

DEBIAN: 2025:1247-2 Critical: KRB5 Security Flaw Buffer Overrun

suse
Calendar Grey April 8, 2024
Dist Suse Esm H88
Important flaw resolution for krb5 tackles memory vulnerabilities in SUSE Linux. Prompt application of this patch is essential to reduce potential threats.
* bsc#1220770 * bsc#1220771 Cross-References: * CVE-2024-26458

Summary

## This update for krb5 fixes the following issues: * CVE-2024-26458: Fixed a memory leak in pmap_rmt.c (bsc#1220770) * CVE-2024-26461: Fixed a memory leak in k5sealv3.c (bsc#1220771) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1148=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1148=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1148=1 * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-1148=1

References

* bsc#1220770

* bsc#1220771

Cross-

* CVE-2024-26458

* CVE-2024-26461

CVSS scores:

* CVE-2024-26458 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-26461 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* SUSE Linux Enterprise High Performance Computing 12 SP5

* SUSE Linux Enterprise Server 12 SP5

* SUSE Linux Enterprise Server for SAP Applications 12 SP5

* SUSE Linux Enterprise Software Development Kit 12 SP5

An update that solves two vulnerabilities can now be installed.

##

* https://www.suse.com/security/cve/CVE-2024-26458.html

* https://www.suse.com/security/cve/CVE-2024-26461.html

* https://bugzilla.suse.com/show_bug.cgi?id=1220770

* https://bugzilla.suse.com/show_bug.cgi?id=1220771

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:1148-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here