CVE-2017-11368: Fedoraproject Fedora

Medium severity, CVSS 6.5. EPSS: 2.4% chance of exploitation in the next 30 days.

In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.

Affected products

  • Fedoraproject Fedora: version 25 only; version 26 only
  • Mit Kerberos: version 5-1.13.7 only
  • Mit Kerberos 5: version 1.7 only; version 1.7.1 only; version 1.8 only; version 1.8.1 only; version 1.8.2 only; version 1.8.3 only; …

Published 2017-08-09. Last modified 2026-06-17.