Mmastodon TechnologyCybersecurity first seen 5 h ago, last 5 h ago, peak #12
MIT Kerberos 5 vulnerability could let clients crash services
Original: π¨ EUVD-2026-95256 π Score: 7.1/10 (CVSS v3.1) π¦ Product: krb5 π’ Vendor: MIT π Updated: 2026-10-08 π MIT Kerberos 5 (krb5
A newly catalogued vulnerability, EUVD-2026-95256, affects MIT Kerberos 5 (krb5) through version 1.22.2. The flaw is a NULL pointer dereference in the make_cred_list() function in rd_cred.c, which could allow authenticated Kerberos clients to crash services by sending crafted credential data. The issue carries a CVSS v3.1 score of 7.1 out of 10 and was updated on 8 October 2026. Administrators running Kerberos authentication infrastructure are expected to monitor for patches from MIT.
Why now: Kerberos is widely used for network authentication, so a high-severity denial-of-service flaw in it matters to system administrators.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1542329