CVE-2023-36054: Debian Linux

Medium severity, CVSS 6.5. EPSS: 2.8% chance of exploitation in the next 30 days.

lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Mit Kerberos 5: before 1.20.2 (fixed in 1.20.2); version 1.21 only
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Clustered Data Ontap: version 9.0 only
  • Netapp Hci: affected versions not specified
  • Netapp Management Services For Element Software: affected versions not specified
  • Netapp Ontap Tools: affected versions not specified

Published 2023-08-07. Last modified 2026-06-17.