{"id":"CVE-2023-36054","details":"lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.","modified":"2026-08-12T14:51:06.579932Z","published":"2023-08-07T00:00:00Z","related":["ALSA-2023:6699","SUSE-SU-2023:3325-1","SUSE-SU-2023:3363-1","SUSE-SU-2023:3365-1","SUSE-SU-2023:3398-1","SUSE-SU-2023:3434-1","openSUSE-SU-2024:13050-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/36xxx/CVE-2023-36054.json"},"references":[{"type":"WEB","url":"https://github.com/krb5/krb5/compare/krb5-1.20.1-final...krb5-1.20.2-final"},{"type":"WEB","url":"https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/36xxx/CVE-2023-36054.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-36054"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20230908-0004/"},{"type":"ADVISORY","url":"https://web.mit.edu/kerberos/www/advisories/"},{"type":"FIX","url":"https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/krb5/krb5","events":[{"introduced":"0"},{"fixed":"47646c2b98fb17f06e5c46ec1348dd54ad65ef83"},{"introduced":"7efe9fc3551f0e1368fb6b7832161ebad942ed72"},{"fixed":"ef08b09c9459551aabbe7924fb176f1583053cdd"}],"database_specific":{"cpe":["cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*","cpe:2.3:a:mit:kerberos_5:1.21:-:*:*:*:*:*:*","cpe:2.3:a:mit:kerberos_5:1.21:beta1:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"1.20.2"},{"introduced":"1.21-NA"},{"last_affected":"1.21-NA"},{"introduced":"1.21-beta1"},{"last_affected":"1.21-beta1"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["1.21-NA","1.21-beta1","krb5-1.20.1-final","krb5-1.20-final","krb5-1.20-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-36054.json","vanir_signatures_modified":"2026-08-12T14:51:06Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd","target":{"file":"src/lib/kadm5/kadm_rpc_xdr.c","function":"_xdr_kadm5_principal_ent_rec"},"deprecated":false,"digest":{"length":1784,"function_hash":"292458871393797026895224770310205177433"},"id":"CVE-2023-36054-470cf1b5","signature_type":"Function"},{"target":{"file":"src/lib/kadm5/kadm_rpc_xdr.c"},"deprecated":false,"digest":{"line_hashes":["334156890665377397254782129423192701014","291711314844331628929990863608957466062","78628825109575425569660732236780644162","261916500496618123580874075940328985736","30376023932640832738304776029120750510","52577924269244501238970656709228176349","142673664801473503695693422137628437538","247089036493975321463435678447079451818","268291072872507344209176579942598505100","283004837450157505273504451698654990402","198860051218332904966840358757088003952","332792275552660967371033837008166398627","181968824239837814858031817203727806594","289882732570170768537025219367137493777"],"threshold":0.9},"id":"CVE-2023-36054-ea2fc528","signature_type":"Line","signature_version":"v1","source":"https://github.com/krb5/krb5/commit/ef08b09c9459551aabbe7924fb176f1583053cdd"}]}}],"schema_version":"1.9.0"}