PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107708 MIT CVE debrief

A NULL pointer dereference vulnerability exists in MIT krb5 through version 1.22.2 in the KDC's handling of S4U2Proxy requests with malformed client names. This issue allows a malicious cross-realm trusted KDC to crash the krb5kdc service, potentially denying authentication. The vulnerability is caused by the KDC's failure to properly validate client names, leading to a NULL pointer dereference. Defenders should be aware of the potential impact on authentication services and take steps to verify exposure and apply patches or mitigations as needed.

Vendor
MIT
Product
krb5
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for MIT krb5 installations, particularly those using versions through 1.22.2, should assess exposure and prioritize patching or mitigation efforts. This includes verifying system configurations, reviewing monitoring and detection capabilities, and applying patches or updates as available. Defenders should also be aware of the potential impact on authentication services and take steps to verify exposure and apply patches or mitigations

Why it matters

This vulnerability allows a malicious cross-realm trusted KDC to crash the krb5kdc service by sending S4U2Proxy requests with malformed client names, potentially denying authentication. Defenders should verify exposure, especially for MIT krb5 versions through 1.22.2, and prioritize patching.

  • Potential denial of authentication service
  • Service disruption due to krb5kdc crashes
  • Need for verification of system exposure and patching

Technical summary

The MIT krb5 KDC is vulnerable to a NULL pointer dereference when handling S4U2Proxy requests with malformed client names. This can lead to a crash of the krb5kdc service, potentially denying authentication. The vulnerability is caused by the KDC's failure to properly validate client names, leading to a NULL pointer dereference. Defenders should prioritize verifying exposure of MIT krb5 installations to this vulnerability, assessing whether systems are vulnerable, and applying patches or mitigations as available. The vulnerability affects MIT krb5 through version 1.22.2.

Defensive priority

Defenders should prioritize verifying exposure of MIT krb5 installations to this vulnerability, assessing whether systems are vulnerable, and applying patches or mitigations as available.

Recommended defensive actions

  • Verify MIT krb5 version and assess exposure
  • Review system configurations for potential vulnerabilities
  • Apply patches or updates when available
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including its existence in MIT krb5 through 1.22.2, the affected component (KDC), and the potential impact of a denial of authentication service. The vulnerability is related to the KDC's handling of S4U2Proxy requests with malformed client names. Defenders should verify exposure, especially for MIT krb5 versions through 1.22.2, and prioritize patching. The source item provides additional context on the vulnerability, including its potential impact on authentication.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107708 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107708

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107708 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107708

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • MIT krb5 through 1.22.2 KDC NULL Pointer Dereference via S4U2Proxy PAC

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107708.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/krb5/krb5/pull/1510

    Supplemental source - issue-tracking, patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/krb5/krb5/commit/f6e2c397ceda6467ebbaab8ed66d4895c9f1d6a7

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/krb5/krb5/commit/a88a18cafa1040a0c4f9c8d08288fc98831ec86d

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/krb5/krb5/blob/krb5-1.22.2-final/src/kdc/kdc_util.c

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/krb5/krb5

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/mit-krb5-through-1.22.2-kdc-null-pointer-dereference-via-s4u2proxy-pac

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.