CVE-2024-26458

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mit:kerberos_5:1.21.2:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:cloud_volumes_ontap_mediator:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_9:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h615c:-:*:*:*:*:*:*:*

History

23 May 2025, 15:39

Type Values Removed Values Added
First Time Netapp h610s
Netapp ontap 9
Netapp active Iq Unified Manager
Netapp
Netapp h610s Firmware
Mit
Netapp ontap Select Deploy Administration Utility
Netapp h610c Firmware
Netapp h615c Firmware
Mit kerberos 5
Netapp management Services For Element Software And Netapp Hci
Netapp cloud Volumes Ontap Mediator
Netapp h610c
Netapp h615c
References () https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md - () https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md - Exploit
References () https://security.netapp.com/advisory/ntap-20240415-0010/ - () https://security.netapp.com/advisory/ntap-20240415-0010/ - Third Party Advisory
CWE CWE-401
CPE cpe:2.3:a:netapp:cloud_volumes_ontap_mediator:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h615c:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_9:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.21.2:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*

06 Dec 2024, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

21 Nov 2024, 09:02

Type Values Removed Values Added
References () https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md - () https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md -
References () https://security.netapp.com/advisory/ntap-20240415-0010/ - () https://security.netapp.com/advisory/ntap-20240415-0010/ -

14 May 2024, 15:09

Type Values Removed Values Added
Summary
  • (es) Kerberos 5 (también conocido como krb5) 1.21.2 contiene una pérdida de memoria en /krb5/src/lib/rpc/pmap_rmt.c.
References
  • () https://security.netapp.com/advisory/ntap-20240415-0010/ -

29 Feb 2024, 01:44

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-29 01:44

Updated : 2025-05-23 15:39


NVD link : CVE-2024-26458

Mitre link : CVE-2024-26458

CVE.ORG link : CVE-2024-26458


JSON object : View

Products Affected

netapp

  • h615c_firmware
  • ontap_select_deploy_administration_utility
  • cloud_volumes_ontap_mediator
  • h610s
  • h615c
  • active_iq_unified_manager
  • management_services_for_element_software_and_netapp_hci
  • h610c
  • h610s_firmware
  • h610c_firmware
  • ontap_9

mit

  • kerberos_5
CWE
CWE-401

Missing Release of Memory after Effective Lifetime