CVE-2024-26458

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:mit:kerberos_5:1.21.2:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:cloud_volumes_ontap_mediator:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_9:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h615c:-:*:*:*:*:*:*:*

History

23 May 2025, 15:39

Type Values Removed Values Added
CWE CWE-401
CPE cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:cloud_volumes_ontap_mediator:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_9:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.21.2:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:h:netapp:h615c:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
First Time Netapp ontap 9
Netapp h615c
Mit
Netapp h610c
Netapp cloud Volumes Ontap Mediator
Netapp h610s
Netapp ontap Select Deploy Administration Utility
Mit kerberos 5
Netapp h615c Firmware
Netapp h610c Firmware
Netapp h610s Firmware
Netapp
Netapp active Iq Unified Manager
Netapp management Services For Element Software And Netapp Hci
References () https://security.netapp.com/advisory/ntap-20240415-0010/ - () https://security.netapp.com/advisory/ntap-20240415-0010/ - Third Party Advisory
References () https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md - () https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md - Exploit

14 May 2024, 15:09

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240415-0010/ -

29 Feb 2024, 01:44

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-29 01:44

Updated : 2025-05-23 15:39


NVD link : CVE-2024-26458

Mitre link : CVE-2024-26458


JSON object : View

Products Affected

netapp

  • h615c_firmware
  • management_services_for_element_software_and_netapp_hci
  • h610c
  • h610s_firmware
  • cloud_volumes_ontap_mediator
  • h610s
  • h615c
  • active_iq_unified_manager
  • ontap_select_deploy_administration_utility
  • h610c_firmware
  • ontap_9

mit

  • kerberos_5
CWE
CWE-401

Missing Release of Memory after Effective Lifetime