{"id":"AZL-106839","summary":"CVE-2026-107778 affecting package krb5 1.21.3-5","details":"MIT Kerberos 5 (krb5) through 1.22.2 contains a NULL pointer dereference in make_cred_list() in rd_cred.c that allows authenticated Kerberos clients to crash services by sending mismatched KRB-CRED arrays. Attackers can send forwarded credentials with more tickets than ticket_info entries through gss_accept_sec_context() to crash GSS-API acceptor services, causing denial of service.","modified":"2026-10-09T14:17:20.666441217Z","published":"2026-10-08T21:17:52Z","upstream":["CVE-2026-107778"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107778"}],"affected":[{"package":{"name":"krb5","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/krb5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.21.3-5"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106839.json"}}],"schema_version":"1.9.0"}