Alibaba Cloud Linux 2.1903 Security Advisory: ALINUX2-SA-2021:0068

Issued: 2021-11-24
Updated: 2021-11-24

Summary

krb5 security update

Severity

Moderate

Description

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities:

CVE-2021-37750:
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.

References

Updated Packages