CVE-2024-26458 describes a memory leak vulnerability in Kerberos 5 (krb5) version 1.21.2, specifically within the pmap_rmt.c component, affecting products from MIT and NetApp. Rated 5.3 MEDIUM, this vulnerability has a network attack vector and low attack complexity, potentially leading to a loss of confidentiality. There is currently no evidence of active exploitation, no public exploit code available, and minimal community discussion or media coverage, indicating low immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.21.2CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.21.2:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:cloud_volumes_ontap_mediator:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:ontap_9:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk User Behavior Analytics (UBA) - July 2025
Jul 30, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025CVE-2024-26458
Dec 10, 2024CVE-2024-26458
Oct 8, 2024krb5: Memory leak at /krb5/src/lib/rpc/pmap_rmt.c
Feb 28, 2024Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
Feb 13, 2024