[17141] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

[krbdev.mit.edu #9235] git commit

daemon@ATHENA.MIT.EDU (Greg Hudson via RT)
Fri Sep 4 20:00:18 2026

From: "Greg Hudson via RT" <rt@krbdev.mit.edu>
In-Reply-To: 
Message-ID: <rt-4.4.3-2-3088904-1788566412-1630.9235-5-0@mit.edu>
To: "AdminCc of krbdev.mit.edu Ticket #9235":;
Date: Fri, 04 Sep 2026 20:00:12 -0400
MIME-Version: 1.0
Reply-To: rt@krbdev.mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krb5-bugs-bounces@mit.edu


<URL: https://krbdev.mit.edu/rt/Ticket/Display.html?id=9235 >


Free small client memory leak on OTP failure

When an initial credentials request using FAST OTP fails due to a
rejection from the KDC, otp_client_prep_questions() may be called
during the processing of the PREAUTH_FAILED response, due to a minor
malfunction in the preauth logic (to be fixed separately).  When this
happens the OTP challenge in the PREAUTH_FAILED padata is decoded into
modreq, overwriting and leaking the decoded challenge from the
PREAUTH_REQUIRED response.

Although we don't expect multiple otp_client_prep_questions() calls
when the preauth logic is behaving properly, it could still happen due
to unexpected KDC behavior (such as a MORE_PREAUTH_DATA_REQUIRED
response).  Fix the leak in otp_client_prep_questions() so that it
isn't admitted under any KDC behavior.

(cherry picked from commit 82a4224f07ad21c2a3e977c5c4651d7d30c6f1f0)

https://github.com/krb5/krb5/commit/e689b5d54d90a45f4d03ccbdae40fb4037276ea7
Author: Greg Hudson <ghudson@mit.edu>
Commit: e689b5d54d90a45f4d03ccbdae40fb4037276ea7
Branch: krb5-1.22
 src/lib/krb5/krb/preauth_otp.c | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

_______________________________________________
krb5-bugs mailing list
krb5-bugs@mit.edu
https://mailman.mit.edu/mailman/listinfo/krb5-bugs

home help back first fref pref prev next nref lref last post