CVE-2025-24528 is an integer overflow vulnerability in MIT Kerberos 5 (krb5) versions prior to 1.22, specifically within the kdb_log.c component when using incremental propagation. An authenticated attacker can trigger an out-of-bounds write by providing a large update size, leading to a denial-of-service condition by crashing the kadmind daemon. This vulnerability has a CVSS score of 7.1 (HIGH), indicating a network-based attack with high impact on availability and low impact on integrity, requiring low privileges and high attack complexity. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion with 10 mentions, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.7, < 1.22CPE match | cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.
Jan 13, 2026HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025krb5: overflow when calculating ulog block size
Jan 28, 2024