{"id":"AZL-74852","summary":"CVE-2025-24528 affecting package krb5 for versions less than 1.21.3-3","details":"In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.","modified":"2026-04-01T05:22:46.744246Z","published":"2026-01-16T18:16:06Z","upstream":["CVE-2025-24528"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24528"}],"affected":[{"package":{"name":"krb5","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/krb5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.21.3-3"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-74852.json"}}],"schema_version":"1.7.5"}