PatchSiren cyber security CVE debrief
CVE-2026-107708 MIT CVE debrief
A NULL pointer dereference vulnerability exists in MIT krb5 through version 1.22.2 in the KDC's handling of S4U2Proxy requests with malformed client names. This issue allows a malicious cross-realm trusted KDC to crash the krb5kdc service, potentially denying authentication. The vulnerability is caused by the KDC's failure to properly validate client names, leading to a NULL pointer dereference. Defenders should be aware of the potential impact on authentication services and take steps to verify exposure and apply patches or mitigations as needed.
- Vendor
- MIT
- Product
- krb5
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for MIT krb5 installations, particularly those using versions through 1.22.2, should assess exposure and prioritize patching or mitigation efforts. This includes verifying system configurations, reviewing monitoring and detection capabilities, and applying patches or updates as available. Defenders should also be aware of the potential impact on authentication services and take steps to verify exposure and apply patches or mitigations
Why it matters
This vulnerability allows a malicious cross-realm trusted KDC to crash the krb5kdc service by sending S4U2Proxy requests with malformed client names, potentially denying authentication. Defenders should verify exposure, especially for MIT krb5 versions through 1.22.2, and prioritize patching.
- Potential denial of authentication service
- Service disruption due to krb5kdc crashes
- Need for verification of system exposure and patching
Technical summary
The MIT krb5 KDC is vulnerable to a NULL pointer dereference when handling S4U2Proxy requests with malformed client names. This can lead to a crash of the krb5kdc service, potentially denying authentication. The vulnerability is caused by the KDC's failure to properly validate client names, leading to a NULL pointer dereference. Defenders should prioritize verifying exposure of MIT krb5 installations to this vulnerability, assessing whether systems are vulnerable, and applying patches or mitigations as available. The vulnerability affects MIT krb5 through version 1.22.2.
Defensive priority
Defenders should prioritize verifying exposure of MIT krb5 installations to this vulnerability, assessing whether systems are vulnerable, and applying patches or mitigations as available.
Recommended defensive actions
- Verify MIT krb5 version and assess exposure
- Review system configurations for potential vulnerabilities
- Apply patches or updates when available
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including its existence in MIT krb5 through 1.22.2, the affected component (KDC), and the potential impact of a denial of authentication service. The vulnerability is related to the KDC's handling of S4U2Proxy requests with malformed client names. Defenders should verify exposure, especially for MIT krb5 versions through 1.22.2, and prioritize patching. The source item provides additional context on the vulnerability, including its potential impact on authentication.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107708 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107708
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107708 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107708
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
MIT krb5 through 1.22.2 KDC NULL Pointer Dereference via S4U2Proxy PAC
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107708.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/krb5/krb5/pull/1510
Supplemental source - issue-tracking, patch
-
Source reference
Unverified legacy reference
URL: https://github.com/krb5/krb5/commit/f6e2c397ceda6467ebbaab8ed66d4895c9f1d6a7
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/krb5/krb5/commit/a88a18cafa1040a0c4f9c8d08288fc98831ec86d
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/krb5/krb5/blob/krb5-1.22.2-final/src/kdc/kdc_util.c
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/krb5/krb5
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/mit-krb5-through-1.22.2-kdc-null-pointer-dereference-via-s4u2proxy-pac
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.