An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c.
An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.
AI Analysis
Technical Summary
The vulnerability in MIT krb5's berval2tl_data() function arises from an unsigned subtraction (bv_len - 2) without prior bounds checking. When bv_len is less than 2, the subtraction underflows, wrapping to a large value truncated to uint16_t, causing malloc to allocate a large buffer and memcpy to read beyond the actual buffer size. This results in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len less than 2, which triggers the underflow when the Kerberos KDC or kadmind reads principal data. This affects numerous Ubuntu krb5 package versions as listed.
Potential Impact
The vulnerability causes a heap out-of-bounds read, which can lead to denial of service (application crash) or potentially information disclosure. The CVSS vector indicates network attack complexity is high and requires high privileges, with no user interaction needed, and impacts availability severely and confidentiality to a low degree. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid using untrusted or compromised LDAP KDB backends that could return malformed krbExtraData attributes. Monitor vendor channels for updates and apply patches promptly once released.
An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c.
Description
An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.
CVSS v3.1
Score 5.0medium
Affected software
pkg:deb/ubuntu/[email protected]+dfsg-2ubuntu5.4+esm7?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+dfsg-5ubuntu2.2+esm7?arch=source&distro=esm-infra/xenialpkg:deb/ubuntu/[email protected]+esm5?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in MIT krb5's berval2tl_data() function arises from an unsigned subtraction (bv_len - 2) without prior bounds checking. When bv_len is less than 2, the subtraction underflows, wrapping to a large value truncated to uint16_t, causing malloc to allocate a large buffer and memcpy to read beyond the actual buffer size. This results in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len less than 2, which triggers the underflow when the Kerberos KDC or kadmind reads principal data. This affects numerous Ubuntu krb5 package versions as listed.
Potential Impact
The vulnerability causes a heap out-of-bounds read, which can lead to denial of service (application crash) or potentially information disclosure. The CVSS vector indicates network attack complexity is high and requires high privileges, with no user interaction needed, and impacts availability severely and confidentiality to a low degree. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid using untrusted or compromised LDAP KDB backends that could return malformed krbExtraData attributes. Monitor vendor channels for updates and apply patches promptly once released.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-11850
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a58b41868715ace43d686db
Added to database: 07/16/2026, 10:36:08 UTC
Last enriched: 07/16/2026, 10:59:05 UTC
Last updated: 07/31/2026, 19:24:48 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.