Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-74852.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-74852
Upstream
Published
2026-01-16T18:16:06Z
Modified
2026-04-01T05:22:46.744246Z
Summary
CVE-2025-24528 affecting package krb5 for versions less than 1.21.3-3
Details

In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.

References

Affected packages

Azure Linux:3 / krb5

Package

Name
krb5
Purl
pkg:rpm/azure-linux/krb5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.21.3-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-74852.json"