CVE-2024-26461

K

erberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.

Configurations

Configuration 1 (hide)

cpe:2.3:a:mit:kerberos_5:1.21.2:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:cloud_volumes_ontap_mediator:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_9:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h615c:-:*:*:*:*:*:*:*

History

23 May 2025, 15:30

Type Values Removed Values Added
CPE cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h615c:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_9:-:*:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.21.2:*:*:*:*:*:*:*
cpe:2.3:a:netapp:cloud_volumes_ontap_mediator:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:*
First Time Netapp h615c Firmware
Netapp h610s Firmware
Netapp management Services For Element Software And Netapp Hci
Netapp h610s
Netapp h615c
Netapp h610c Firmware
Netapp ontap 9
Netapp ontap Select Deploy Administration Utility
Netapp active Iq Unified Manager
Mit
Netapp cloud Volumes Ontap Mediator
Netapp
Netapp h610c
Mit kerberos 5
References () https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md - () https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md - Exploit
References () https://security.netapp.com/advisory/ntap-20240415-0011/ - () https://security.netapp.com/advisory/ntap-20240415-0011/ - Third Party Advisory

21 Nov 2024, 09:02

Type Values Removed Values Added
References () https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md - () https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md -
References () https://security.netapp.com/advisory/ntap-20240415-0011/ - () https://security.netapp.com/advisory/ntap-20240415-0011/ -

14 Aug 2024, 16:35

Type Values Removed Values Added
CWE CWE-770
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

14 May 2024, 15:09

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240415-0011/ -

Information

Published : 2024-02-29 01:44

Updated : 2025-05-23 15:30


NVD link : CVE-2024-26461

Mitre link : CVE-2024-26461

CVE.ORG link : CVE-2024-26461


JSON object : View

CWE
CWE-770

Allocation of Resources Without Limits or Throttling