Bug 1278951 (CVE-2015-2698) - CVE-2015-2698 krb5: IAKERB context export/import
Summary: CVE-2015-2698 krb5: IAKERB context export/import
Alias: CVE-2015-2698
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 1278952
Blocks: 1275873
TreeView+ depends on / blocked
Reported: 2015-11-06 20:22 UTC by Kurt Seifried
Modified: 2019-09-29 13:39 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2015-12-10 10:09:27 UTC

Attachments (Terms of Use)

Description Kurt Seifried 2015-11-06 20:22:53 UTC
The kerberos project reports:

The patches for CVE-2015-2696 contained a regression in the newly
added IAKERB iakerb_gss_export_sec_context() function, which could
cause it to corrupt memory.  Fix the regression by properly
dereferencing the context_handle pointer before casting it.

Also, the patches did not implement an IAKERB gss_import_sec_context()
function, under the erroneous belief that an exported IAKERB context
would be tagged as a krb5 context.  Implement it now to allow IAKERB
contexts to be successfully exported and imported after establishment.


In any MIT krb5 release with the patches for CVE-2015-2696 applied, an
application which calls gss_export_sec_context() may experience memory
corruption if the context was established using the IAKERB mechanism.
Historically, some vulnerabilities of this nature can be translated
into remote code execution, though the necessary exploits must be
tailored to the individual application and are usually quite

External reference:

Comment 1 Kurt Seifried 2015-11-06 20:23:53 UTC
Created krb5 tracking bugs for this issue:

Affects: fedora-all [bug 1278952]

Comment 3 Stefan Cornelius 2015-12-10 10:08:45 UTC

This issue did not affect the versions of krb5 as shipped with Red Hat Enterprise Linux 4, 5, 6, and 7.

Note You need to log in before you can comment on or make changes to this bug.