krb5 commit: Fix KDC null deref on TGS inner body null server

Greg Hudson <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.cvs
Message-ID <[email protected]>
https://github.com/krb5/krb5/commit/d775c95af7606a51bf79547a94fa52ddd1cb7f49
commit d775c95af7606a51bf79547a94fa52ddd1cb7f49
Author: Greg Hudson <[email protected]>
Date:   Tue Aug 3 01:15:27 2021 -0400

    Fix KDC null deref on TGS inner body null server
    
    After the KDC decodes a FAST inner body, it does not check for a null
    server.  Prior to commit 39548a5b17bbda9eeb63625a201cfd19b9de1c5b this
    would typically result in an error from krb5_unparse_name(), but with
    the addition of get_local_tgt() it results in a null dereference.  Add
    a null check.
    
    Reported by Joseph Sutton of Catalyst.
    
    CVE-2021-37750:
    
    In MIT krb5 releases 1.14 and later, an authenticated attacker can
    cause a null dereference in the KDC by sending a FAST TGS request with
    no server field.
    
    ticket: 9008 (new)
    tags: pullup
    target_version: 1.19-next
    target_version: 1.18-next

 src/kdc/do_tgs_req.c |    5 +++++
 1 files changed, 5 insertions(+), 0 deletions(-)

diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c
index 582e497..32dc65f 100644
--- a/src/kdc/do_tgs_req.c
+++ b/src/kdc/do_tgs_req.c
@@ -204,6 +204,11 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt,
         status = "FIND_FAST";
         goto cleanup;
     }
+    if (sprinc == NULL) {
+        status = "NULL_SERVER";
+        errcode = KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN;
+        goto cleanup;
+    }
 
     errcode = get_local_tgt(kdc_context, &sprinc->realm, header_server,
                             &local_tgt, &local_tgt_storage, &local_tgt_key);
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.