Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 20.04 and 18.04 USN-5959-1 Critical Kerberos Denial of Service

ubuntu
Calendar Grey March 17, 2023
Scroller Ubuntu
Protect your Ubuntu machine from emerging krb5 vulnerabilities that impact LTS editions. It's essential to apply updates without delay.
Several security issues were fixed in Kerberos.

Summary

Several security issues were fixed in Kerberos.

Software Description:

- krb5: MIT Kerberos Network Authentication Protocol

Details:

It was discovered that Kerberos incorrectly handled memory when processing

KDC data, which could lead to a NULL pointer dereference. An attacker could

possibly use this issue to cause a denial of service or have other

unspecified impacts. (CVE-2021-36222, CVE-2021-37750)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  krb5-k5tls                      1.17-6ubuntu4.3
  krb5-kdc                        1.17-6ubuntu4.3
  krb5-kdc-ldap                   1.17-6ubuntu4.3
  krb5-pkinit                     1.17-6ubuntu4.3

Ubuntu 18.04 LTS:
  krb5-k5tls                      1.16-2ubuntu0.4
  krb5-kdc                        1.16-2ubuntu0.4
  krb5-kdc-ldap                   1.16-2ubuntu0.4
  krb5-pkinit                     1.16-2ubuntu0.4

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5959-1

CVE-2021-36222, CVE-2021-37750

Severity
critical
Lowest
Low
Medium
High
Critical

March 16, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.