Bug 2274401 (CVE-2024-3657)

Summary: CVE-2024-3657 389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request
Product: [Other] Security Response Reporter: Robb Gatica <rgatica>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: ahanwate, bsmejkal, idm-ds-dev-bugs, jachapma, musoni, osci-admins+erratabot, progier, security-response-team, spichugi, ssidhaye, tbordaz, teagle, vashirov
Target Milestone: ---Keywords: Security
Target Release: ---Flags: tbordaz: needinfo? (rgatica)
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: 389-ds-base-2.5.1 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2275857, 2275858, 2275859, 2275860, 2276882, 2283631, 2290379, 2290401, 2290549    
Bug Blocks: 2274406    

Description Robb Gatica 2024-04-10 20:31:48 UTC
Details:
We received a report that a specially-crafted Kerberos AS-REQ packet can potentially cause a denial of service. Per the reporter: "A specially crafted Kerberos AS-REQ request may cause a failure on the directory server. 

Tested FreeIPA version:
ipa-server-4.10.3

Steps to reproduce (see attachments):
1. Make request: kinit $(cat poc.txt)
2. Check krb5kdc log and ipactl status. (Directory Service: Stopped)

Comment 20 Sandipan Roy 2024-05-28 11:48:17 UTC
Created 389-ds-base tracking bugs for this issue:

Affects: fedora-all [bug 2283631]

Comment 21 errata-xmlrpc 2024-06-04 14:20:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2024:3591 https://access.redhat.com/errata/RHSA-2024:3591

Comment 22 errata-xmlrpc 2024-06-11 19:42:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:3837 https://access.redhat.com/errata/RHSA-2024:3837

Comment 23 errata-xmlrpc 2024-06-25 11:11:22 UTC
This issue has been addressed in the following products:

  Red Hat Directory Server 12.4 for RHEL 9

Via RHSA-2024:4092 https://access.redhat.com/errata/RHSA-2024:4092

Comment 24 errata-xmlrpc 2024-07-02 07:59:16 UTC
This issue has been addressed in the following products:

  Red Hat Directory Server 11.8 for RHEL 8

Via RHSA-2024:4209 https://access.redhat.com/errata/RHSA-2024:4209

Comment 25 errata-xmlrpc 2024-07-02 08:16:24 UTC
This issue has been addressed in the following products:

  Red Hat Directory Server 11.9 for RHEL 8

Via RHSA-2024:4210 https://access.redhat.com/errata/RHSA-2024:4210

Comment 26 errata-xmlrpc 2024-07-02 15:21:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:4235 https://access.redhat.com/errata/RHSA-2024:4235

Comment 27 errata-xmlrpc 2024-07-18 15:17:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2024:4633 https://access.redhat.com/errata/RHSA-2024:4633

Comment 28 errata-xmlrpc 2024-08-21 11:53:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2024:5690 https://access.redhat.com/errata/RHSA-2024:5690

Comment 29 errata-xmlrpc 2024-09-11 06:35:52 UTC
This issue has been addressed in the following products:

  Red Hat Directory Server 11.7 for RHEL 8

Via RHSA-2024:6576 https://access.redhat.com/errata/RHSA-2024:6576

Comment 30 errata-xmlrpc 2024-10-01 15:51:44 UTC
This issue has been addressed in the following products:

  Red Hat Directory Server 12.2 EUS for RHEL 9

Via RHSA-2024:7458 https://access.redhat.com/errata/RHSA-2024:7458

Comment 33 errata-xmlrpc 2025-02-18 10:13:46 UTC
This issue has been addressed in the following products:

  Red Hat Directory Server 11.5 E4S for RHEL 8

Via RHSA-2025:1632 https://access.redhat.com/errata/RHSA-2025:1632