CVE-2017-7562: Mit Kerberos 5

Medium severity, CVSS 6.5. EPSS: 3.2% chance of exploitation in the next 30 days.

An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw to impersonate arbitrary principals under rare and erroneous circumstances.

Affected products

  • Mit Kerberos 5: from 1.0, before 1.16.1 (fixed in 1.16.1)
  • Red Hat Enterprise Linux: version 7.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2018-07-26. Last modified 2026-06-17.