{"id":"CVE-2026-107708","summary":"MIT krb5 through 1.22.2 KDC NULL Pointer Dereference via S4U2Proxy PAC","details":"MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a malformed client name to crash krb5kdc and deny authentication.","modified":"2026-10-10T02:47:26.056426366Z","published":"2026-10-08T20:15:53.534Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-476"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107708.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107708.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107708"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/mit-krb5-through-1.22.2-kdc-null-pointer-dereference-via-s4u2proxy-pac"},{"type":"FIX","url":"https://github.com/krb5/krb5/commit/a88a18cafa1040a0c4f9c8d08288fc98831ec86d"},{"type":"FIX","url":"https://github.com/krb5/krb5/commit/f6e2c397ceda6467ebbaab8ed66d4895c9f1d6a7"},{"type":"FIX","url":"https://github.com/krb5/krb5/pull/1510"},{"type":"PACKAGE","url":"https://github.com/krb5/krb5"},{"type":"ARTICLE","url":"https://github.com/krb5/krb5/blob/krb5-1.22.2-final/src/kdc/kdc_util.c#L639-L676"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/krb5/krb5","events":[{"introduced":"0"},{"fixed":"8570e77819563e036027e1da789d08ec9333ed4d"},{"fixed":"a88a18cafa1040a0c4f9c8d08288fc98831ec86d"},{"fixed":"f6e2c397ceda6467ebbaab8ed66d4895c9f1d6a7"}],"database_specific":{"extracted_events":[{"introduced":"krb5"},{"fixed":"1.22.2"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["krb5-1.22.1-final","krb5-1.22-final","krb5-1.22-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107708.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}