meta-openembedded/meta-oe/recipes-connectivity
Yi Zhao 06d80777f4 krb5: fix CVE-2021-36222
Source: https://git.openembedded.org/meta-openembedded
MR: 112165
Type: Security Fix
Disposition: Backport from  https://git.openembedded.org/meta-openembedded/commit/meta-oe/recipes-connectivity/krb5?id=69087d69d01a4530e2d588036fcbeaf8856b2ff1
ChangeID: e7cdfd1c4530312b4773103cf58d322451af1421
Description:

CVE-2021-36222:
ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC)
in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2
allows remote attackers to cause a NULL pointer dereference and daemon
crash. This occurs because a return value is not properly managed in a
certain situation.

References:
https://nvd.nist.gov/vuln/detail/CVE-2021-36222

Patches from:
fc98f520ca

Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit 620badcbf8a59fbd2cdda6ab01c4ffba1c3ee327)
Signed-off-by: Armin Kuster <akuster808@gmail.com>
(cherry picked from commit 523f6d834d2fddb0ecc73c6d7d8b1845f65f5279)
[Fixup for Dunfell context]
Signed-off-by: Armin Kuster <akuster@mvista.com>
2021-09-10 13:23:06 -07:00
..
2020-01-22 09:56:34 -08:00
2019-12-20 16:07:50 -08:00
2020-02-27 08:25:49 -08:00
2020-09-19 11:22:44 -07:00
2021-09-10 13:23:06 -07:00
2020-03-19 09:26:02 -07:00
2020-02-27 08:25:49 -08:00
2020-02-27 17:55:23 -08:00
2018-06-27 22:17:33 -07:00
2020-05-28 21:39:56 -07:00
2021-02-04 22:39:02 -08:00
2021-05-14 10:03:51 -07:00
2019-01-30 13:34:49 -08:00
2019-11-01 17:22:53 -07:00
2020-05-28 21:49:10 -07:00
2018-04-13 12:43:37 -07:00
2019-12-20 16:07:50 -08:00
2019-12-26 19:52:55 -08:00