Hide Forgot
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit. Upstream Reference: https://krbdev.mit.edu/rt/Ticket/Display.html?id=8959
Patch: https://github.com/krb5/krb5/commit/57415dda6cf04e73ffc3723be518eddfae599bfd
Any plan to get this fixed in RHEL 8? I see 1.18.2 shipped in RHEL 8.3 so it should be affected right?
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:1593 https://access.redhat.com/errata/RHSA-2021:1593
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-28196
This issue has been addressed in the following products: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Via RHSA-2021:2239 https://access.redhat.com/errata/RHSA-2021:2239