CVE-2026-107708
Awaiting Analysis Awaiting Analysis - Queue

NULL Pointer Dereference in MIT krb5 KDC

Vulnerability report for CVE-2026-107708, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a malformed client name to crash krb5kdc and deny authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
MIT krb5 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MIT krb5 through 1.22.2 has a NULL pointer dereference flaw in the KDC's get_pac_princ_with_realm() function. When processing a malformed client name in an S4U2Proxy request with a PAC, the function incorrectly returns success while leaving the client principal NULL. This can crash krb5kdc and block authentication.

Detection Guidance

This vulnerability involves a NULL pointer dereference in MIT krb5's KDC component. Detection requires monitoring krb5kdc for crashes or unusual behavior during authentication requests. Check logs for segmentation faults or authentication failures in the KDC service. No specific commands are provided in the context to directly detect this issue.

Impact Analysis

This vulnerability allows a malicious or compromised cross-realm trusted KDC to crash the krb5kdc service, causing denial of authentication. Users may be unable to authenticate to services relying on MIT krb5, leading to service disruptions and potential unauthorized access attempts.

Compliance Impact

This vulnerability causes denial of authentication services by crashing krb5kdc, which could disrupt access to critical systems. For GDPR, this may impact availability of personal data processing systems. For HIPAA, it could affect access to protected health information systems. However, specific compliance impacts depend on system configuration and compensating controls.

Mitigation Strategies

Upgrade MIT krb5 to version 1.22.2 or later to address the NULL pointer dereference issue in the KDC's get_pac_princ_with_realm() function.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107708. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart