MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 14 h ago, last 14 h ago, peak #12

MIT Kerberos 5 vulnerability could let clients crash services

Original: 🚨 EUVD-2026-95256 πŸ“Š Score: 7.1/10 (CVSS v3.1) πŸ“¦ Product: krb5 🏒 Vendor: MIT πŸ“… Updated: 2026-10-08 πŸ“ MIT Kerberos 5 (krb5

A newly catalogued vulnerability, EUVD-2026-95256, affects MIT Kerberos 5 (krb5) through version 1.22.2. The flaw is a NULL pointer dereference in the make_cred_list() function in rd_cred.c, which could allow authenticated Kerberos clients to crash services by sending crafted credential data. The issue carries a CVSS v3.1 score of 7.1 out of 10 and was updated on 8 October 2026. Administrators running Kerberos authentication infrastructure are expected to monitor for patches from MIT.

Why now: Kerberos is widely used for network authentication, so a high-severity denial-of-service flaw in it matters to system administrators.

MITKerberos 5EUVD-2026-95256

Open on mastodon β†’

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1542329