Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Link | Tags |
---|---|
https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_3.md | exploit |
https://security.netapp.com/advisory/ntap-20240415-0012/ | third party advisory |