If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through server-side request forgery), they can exploit the fact that kdcproxy does not enforce bounds on TCP response length to conduct a denial-of-service attack. While receiving the KDC's response, kdcproxy copies the entire buffered stream into a new buffer on each recv() call, even when the transfer is incomplete, causing excessive memory allocation and CPU usage. Additionally, kdcproxy accepts incoming response chunks as long as the received data length is not exactly equal to the length indicated in the response header, even when individual chunks or the total buffer exceed the maximum length of a Kerberos message. This allows an attacker to send unbounded data until the connection timeout is reached (approximately 12 seconds), exhausting server memory or CPU resources. Multiple concurrent requests can cause accept queue overflow, denying service to legitimate clients.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade ipa-server-dnsUpgrade ipa-client-commonUpgrade ipa-server-trust-adUpgrade python3-pyusbUpgrade python3-custodiaUpgrade python3-ipalibUpgrade softhsmUpgrade ipa-healthcheck-coreUpgrade slapi-nisUpgrade python3-kdcproxyUpgrade python3-qrcodeUpgrade custodiaUpgrade python3-qrcode-coreUpgrade ipa-client-epnUpgrade softhsm-develUpgrade python3-jwcryptoUpgrade ipa-clientUpgrade ipa-client-sambaUpgrade ipa-selinuxUpgrade python3-ipaclientUpgrade opendnssecUpgrade python3-yubicoUpgrade python3-ipaserverUpgrade python3-ipatestsUpgrade ipa-commonUpgrade ipa-python-compatUpgrade ipa-serverUpgrade ipa-server-commonUpgrade bind-dyndb-ldapUpgrade ipa-healthcheck | Nov 20, 2025 | Nov 12, 2025 |
| Amazon Linux Ami 2 | — | Upgrade python-kdcproxy | May 20, 2026 | May 20, 2026 |
| Oracle_linux | — | Upgrade ipa-python-compatUpgrade ipa-client-commonUpgrade ipa-commonUpgrade ipa-server-trust-adUpgrade python3-custodiaUpgrade ipa-clientUpgrade ipa-client-epnUpgrade softhsm-develUpgrade python3-ipaserverUpgrade opendnssecUpgrade slapi-nisUpgrade python3-pyusbUpgrade softhsmUpgrade python3-qrcode-coreUpgrade python3-yubicoUpgrade ipa-serverUpgrade ipa-server-commonUpgrade bind-dyndb-ldapUpgrade python3-kdcproxyUpgrade ipa-client-sambaUpgrade python3-ipaclientUpgrade ipa-selinuxUpgrade ipa-server-dnsUpgrade ipa-healthcheckUpgrade custodiaUpgrade python3-ipalibUpgrade python-kdcproxyUpgrade ipa-healthcheck-coreUpgrade python3-ipatestsUpgrade python3-jwcryptoUpgrade python3-qrcode | Nov 17, 2025 | Nov 12, 2025 |
| Redhat_linux | — | Upgrade python-kdcproxyUpgrade ipa-client-sambaUpgrade ipa-server-dnsUpgrade ipa-client-commonUpgrade ipa-server-commonUpgrade softhsm-develUpgrade softhsm-debugsourceUpgrade bind-dyndb-ldapUpgrade python3-ipalibUpgrade opendnssec-debugsourceUpgrade python3-pyusbUpgrade python3-ipaserverUpgrade ipa-debuginfoUpgrade ipa-serverUpgrade python3-jwcryptoUpgrade ipa-client-debuginfoUpgrade ipa-python-compatUpgrade opendnssecUpgrade custodiaUpgrade python3-qrcode-coreUpgrade bind-dyndb-ldap-debuginfoUpgrade ipa-clientUpgrade python3-custodiaUpgrade softhsmUpgrade python3-ipaclientUpgrade ipa-commonUpgrade python3-yubicoUpgrade bind-dyndb-ldap-debugsourceUpgrade slapi-nis-debugsourceUpgrade python3-qrcodeUpgrade ipa-healthcheck-coreUpgrade slapi-nisUpgrade ipa-selinuxUpgrade ipa-healthcheckUpgrade softhsm-debuginfoUpgrade ipa-server-trust-adUpgrade ipa-client-epnUpgrade python3-ipatestsUpgrade opendnssec-debuginfoUpgrade ipa-server-trust-ad-debuginfoUpgrade slapi-nis-debuginfoUpgrade python3-kdcproxyUpgrade ipa-debugsourceUpgrade ipa-server-debuginfo | Nov 14, 2025 | Nov 12, 2025 |
| Rocky_linux | — | Upgrade ipa-client-epnUpgrade slapi-nis-debuginfoUpgrade bind-dyndb-ldap-debuginfoUpgrade slapi-nis-debugsourceUpgrade slapi-nisUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-client-sambaUpgrade softhsm-debuginfoUpgrade bind-dyndb-ldap-debugsourceUpgrade ipa-clientUpgrade bind-dyndb-ldapUpgrade ipa-debuginfoUpgrade ipa-debugsourceUpgrade softhsmUpgrade ipa-server-trust-adUpgrade softhsm-debugsourceUpgrade softhsm-develUpgrade opendnssec-debugsourceUpgrade opendnssecUpgrade ipa-serverUpgrade ipa-server-debuginfoUpgrade opendnssec-debuginfoUpgrade ipa-client-debuginfo | Feb 5, 2026 | Nov 21, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub