Bug 34040 - krb5 new security issue CVE-2025-24528
Summary: krb5 new security issue CVE-2025-24528
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-02-24 14:26 CET by Nicolas Salguero
Modified: 2025-02-25 17:59 CET (History)
3 users (show)

See Also:
Source RPM: krb5-1.20.1-1.3.mga9.src.rpm
CVE: CVE-2025-24528
Status comment:


Attachments

Comment 1 Nicolas Salguero 2025-02-24 14:27:44 CET
Fix: https://github.com/krb5/krb5/commit/78ceba024b64d49612375be4a12d1c066b0bfbd0

Status comment: (none) => Patch available from upstream and Fedora
Source RPM: (none) => krb5-1.21.3-2.mga10.src.rpm, krb5-1.20.1-1.3.mga9.src.rpm
Whiteboard: (none) => MGA9TOO
CVE: (none) => CVE-2025-24528

Comment 2 Nicolas Salguero 2025-02-24 16:00:45 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Overflow when calculating ulog block size. (CVE-2025-24528)

References:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VLIGTCER7WVUGDD5KJI3RHPHU5VI7UCF/
========================

Updated packages in core/updates_testing:
========================
krb5-1.20.1-1.4.mga9
krb5-pkinit-1.20.1-1.4.mga9
krb5-server-1.20.1-1.4.mga9
krb5-server-ldap-1.20.1-1.4.mga9
krb5-workstation-1.20.1-1.4.mga9
lib(64)krb53-1.20.1-1.4.mga9
lib(64)krb53-devel-1.20.1-1.4.mga9

from SRPM:
krb5-1.20.1-1.4.mga9.src.rpm

Version: Cauldron => 9
Source RPM: krb5-1.21.3-2.mga10.src.rpm, krb5-1.20.1-1.3.mga9.src.rpm => krb5-1.20.1-1.3.mga9.src.rpm
Status: NEW => ASSIGNED
Status comment: Patch available from upstream and Fedora => (none)
Whiteboard: MGA9TOO => (none)

Nicolas Salguero 2025-02-24 16:00:52 CET

Assignee: bugsquad => qa-bugs

katnatek 2025-02-24 18:48:41 CET

Keywords: (none) => advisory

Comment 3 Herman Viaene 2025-02-25 12:06:59 CET
MGA9-64 Plasma Wayland on Compaq H000SB
No installation issues.
Followed as in bug 33344 Wiki with expected results. Go!!!!

Whiteboard: (none) => MGA9-64-OK
CC: (none) => herman.viaene

Comment 4 Thomas Andrews 2025-02-25 16:02:47 CET
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Comment 5 Mageia Robot 2025-02-25 17:59:08 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0072.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.