yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-26461
Component Overview
Vulnerability Overview
Name
CVE-2024-26461
Source
NVD (
link
)
Debian (
link
)
Description
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
CWEs
CWE-770
Published Date
Feb 29, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md
Exploit
https://security.netapp.com/advisory/ntap-20240415-0011/
Third Party Advisory
https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md
Exploit
https://security.netapp.com/advisory/ntap-20240415-0011/
Third Party Advisory
Analysis
#
Affected Component
Analysis
krb5
Patched
Vulnerability Ratings
#
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libkrb5
buildroot
2025.02.x
1.21.3
Not Affected
libkrb5
buildroot
master
1.22.2
Not Affected
krb5
openwrt
master
1.22.2-r1
Not Affected
krb5
openwrt
openwrt-25.12
1.22.1-r1
Not Affected
krb5
yocto
master
1.22.2
Not Affected
krb5
yocto
scarthgap
1.21.3
Patched
Resolved with patches
#
krb5 (yocto:kirkstone)
#
Title
Author
Resolve
1
Fix two unlikely memory leaks
Greg Hudson <ghudson@mit.edu>
CVE-2024-26458
CVE-2024-26461
krb5 (yocto:scarthgap)
#
Title
Author
Resolve
1
Fix two unlikely memory leaks
Greg Hudson <ghudson@mit.edu>
CVE-2024-26458
CVE-2024-26461