60
CVE-2024-37371
—CVSS 3.1
9.1 critical
EPSS
2%p78
Published
()
Modified
Description
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.