telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval, the telnet service would become unavailable after inetd logs a "telnet/tcp server failing (looping), service terminated" error. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-inetutils | Nov 28, 2022 | Aug 30, 2022 | |
| Dell Powerstore Dsa2023173 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Jun 21, 2023 | |
| Huawei Euleros 2_0_sp9 | huawei-euleros-2_0_sp9-upgrade-telnet | Jul 17, 2024 | Aug 30, 2022 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Aug 30, 2022 | |
| Suse | — | suse-upgrade-krb5-appl-clientssuse-upgrade-krb5-appl-serverssuse-upgrade-telnetsuse-upgrade-telnet-server | Oct 26, 2022 | Aug 30, 2022 |
| Ubuntu | ubuntu-pro-upgrade-inetutils-ftpubuntu-pro-upgrade-inetutils-ftpdubuntu-pro-upgrade-inetutils-inetdubuntu-pro-upgrade-inetutils-pingubuntu-pro-upgrade-inetutils-syslogdubuntu-pro-upgrade-inetutils-talkubuntu-pro-upgrade-inetutils-telnetubuntu-pro-upgrade-inetutils-toolsubuntu-pro-upgrade-inetutils-tracerouteubuntu-upgrade-inetutils-telnetdubuntu-upgrade-inetutils-tools | Aug 23, 2023 | Aug 30, 2022 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Aug 30, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub