Skip to content

[action] [PR:17914] [Security] Fix the krb5 vulnerability issue (#17914)#18002

Merged
mssonicbld merged 1 commit intosonic-net:202311from
mssonicbld:cherry/202311/17914
Feb 2, 2024
Merged

[action] [PR:17914] [Security] Fix the krb5 vulnerability issue (#17914)#18002
mssonicbld merged 1 commit intosonic-net:202311from
mssonicbld:cherry/202311/17914

Conversation

@mssonicbld
Copy link
Collaborator

Why I did it

Fix the krb5 vulnerable issue
CVE-2021-36222 allows remote attackers to cause a NULL pointer dereference and daemon crash
CVE-2021-37750 NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field
DSA 5286-1 remote code execution

Work item tracking
  • Microsoft ADO (number only): 26577929

How I did it

Upgrade the krb5 version to 1.18.3-6+deb11u14+fips.

### Why I did it
Fix the krb5 vulnerable issue
CVE-2021-36222  allows remote attackers to cause a NULL pointer dereference and daemon crash
CVE-2021-37750  NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field
DSA 5286-1  remote code execution

##### Work item tracking
- Microsoft ADO **(number only)**: 26577929

#### How I did it
Upgrade the krb5 version to 1.18.3-6+deb11u14+fips.
@mssonicbld
Copy link
Collaborator Author

Original PR: #17914

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants