krb5 commit [krb5-1.21]: Update for krb5-1.21.2

ghudson at mit.edu ghudson at mit.edu
Mon Aug 14 22:55:16 EDT 2023


https://github.com/krb5/krb5/commit/835f6e3d819beb7ee1046f01afb284b54ad54c5f
commit 835f6e3d819beb7ee1046f01afb284b54ad54c5f
Author: Greg Hudson <ghudson at mit.edu>
Date:   Mon Aug 14 12:16:04 2023 -0400

    Update for krb5-1.21.2

 README                     | 12 ++++++++++++
 src/man/k5identity.man     |  2 +-
 src/man/k5login.man        |  2 +-
 src/man/k5srvutil.man      |  2 +-
 src/man/kadm5.acl.man      |  2 +-
 src/man/kadmin.man         |  2 +-
 src/man/kadmind.man        |  2 +-
 src/man/kdb5_ldap_util.man |  2 +-
 src/man/kdb5_util.man      |  2 +-
 src/man/kdc.conf.man       |  2 +-
 src/man/kdestroy.man       |  2 +-
 src/man/kerberos.man       |  2 +-
 src/man/kinit.man          |  2 +-
 src/man/klist.man          |  2 +-
 src/man/kpasswd.man        |  2 +-
 src/man/kprop.man          |  2 +-
 src/man/kpropd.man         |  2 +-
 src/man/kproplog.man       |  2 +-
 src/man/krb5-config.man    |  2 +-
 src/man/krb5.conf.man      |  2 +-
 src/man/krb5kdc.man        |  2 +-
 src/man/ksu.man            |  2 +-
 src/man/kswitch.man        |  2 +-
 src/man/ktutil.man         |  2 +-
 src/man/kvno.man           |  2 +-
 src/man/sclient.man        |  2 +-
 src/man/sserver.man        |  2 +-
 src/patchlevel.h           |  6 +++---
 src/po/mit-krb5.pot        |  6 +++---
 29 files changed, 44 insertions(+), 32 deletions(-)

diff --git a/README b/README
index 59f5f216b..67c8d108b 100644
--- a/README
+++ b/README
@@ -97,6 +97,18 @@ removed.
 Beginning with the krb5-1.18 release, all support for single-DES
 encryption types has been removed.
 
+Major changes in 1.21.2 (2023-08-14)
+------------------------------------
+
+This is a bug fix release.
+
+* Fix double-free in KDC TGS processing [CVE-2023-39975].
+
+krb5-1.21.2 changes by ticket ID
+--------------------------------
+
+9101    Fix double-free in KDC TGS processing
+
 Major changes in 1.21.1 (2023-07-10)
 ------------------------------------
 
diff --git a/src/man/k5identity.man b/src/man/k5identity.man
index 1f4eff4b3..baf18f9f6 100644
--- a/src/man/k5identity.man
+++ b/src/man/k5identity.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "K5IDENTITY" "5" " " "1.21.1" "MIT Kerberos"
+.TH "K5IDENTITY" "5" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 k5identity \- Kerberos V5 client principal selection rules
 .
diff --git a/src/man/k5login.man b/src/man/k5login.man
index e8d4b28c2..ff3329b92 100644
--- a/src/man/k5login.man
+++ b/src/man/k5login.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "K5LOGIN" "5" " " "1.21.1" "MIT Kerberos"
+.TH "K5LOGIN" "5" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 k5login \- Kerberos V5 acl file for host access
 .
diff --git a/src/man/k5srvutil.man b/src/man/k5srvutil.man
index bbd2bdd47..a6cd9861d 100644
--- a/src/man/k5srvutil.man
+++ b/src/man/k5srvutil.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "K5SRVUTIL" "1" " " "1.21.1" "MIT Kerberos"
+.TH "K5SRVUTIL" "1" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 k5srvutil \- host key table (keytab) manipulation utility
 .
diff --git a/src/man/kadm5.acl.man b/src/man/kadm5.acl.man
index 026af1f6b..8332d5db6 100644
--- a/src/man/kadm5.acl.man
+++ b/src/man/kadm5.acl.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KADM5.ACL" "5" " " "1.21.1" "MIT Kerberos"
+.TH "KADM5.ACL" "5" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kadm5.acl \- Kerberos ACL file
 .
diff --git a/src/man/kadmin.man b/src/man/kadmin.man
index c29638a22..461207021 100644
--- a/src/man/kadmin.man
+++ b/src/man/kadmin.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KADMIN" "1" " " "1.21.1" "MIT Kerberos"
+.TH "KADMIN" "1" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kadmin \- Kerberos V5 database administration program
 .
diff --git a/src/man/kadmind.man b/src/man/kadmind.man
index f295e2c05..fbb6bda99 100644
--- a/src/man/kadmind.man
+++ b/src/man/kadmind.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KADMIND" "8" " " "1.21.1" "MIT Kerberos"
+.TH "KADMIND" "8" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kadmind \- KADM5 administration server
 .
diff --git a/src/man/kdb5_ldap_util.man b/src/man/kdb5_ldap_util.man
index c69be5a12..e11f875ec 100644
--- a/src/man/kdb5_ldap_util.man
+++ b/src/man/kdb5_ldap_util.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KDB5_LDAP_UTIL" "8" " " "1.21.1" "MIT Kerberos"
+.TH "KDB5_LDAP_UTIL" "8" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kdb5_ldap_util \- Kerberos configuration utility
 .
diff --git a/src/man/kdb5_util.man b/src/man/kdb5_util.man
index dac2e1277..dfd2594f4 100644
--- a/src/man/kdb5_util.man
+++ b/src/man/kdb5_util.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KDB5_UTIL" "8" " " "1.21.1" "MIT Kerberos"
+.TH "KDB5_UTIL" "8" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kdb5_util \- Kerberos database maintenance utility
 .
diff --git a/src/man/kdc.conf.man b/src/man/kdc.conf.man
index 6cf7c35f5..394275541 100644
--- a/src/man/kdc.conf.man
+++ b/src/man/kdc.conf.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KDC.CONF" "5" " " "1.21.1" "MIT Kerberos"
+.TH "KDC.CONF" "5" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kdc.conf \- Kerberos V5 KDC configuration file
 .
diff --git a/src/man/kdestroy.man b/src/man/kdestroy.man
index 0cea8aebc..7b1e758fd 100644
--- a/src/man/kdestroy.man
+++ b/src/man/kdestroy.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KDESTROY" "1" " " "1.21.1" "MIT Kerberos"
+.TH "KDESTROY" "1" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kdestroy \- destroy Kerberos tickets
 .
diff --git a/src/man/kerberos.man b/src/man/kerberos.man
index 01876f599..253c9e4b2 100644
--- a/src/man/kerberos.man
+++ b/src/man/kerberos.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KERBEROS" "7" " " "1.21.1" "MIT Kerberos"
+.TH "KERBEROS" "7" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kerberos \- Overview of using Kerberos
 .
diff --git a/src/man/kinit.man b/src/man/kinit.man
index 629226ca1..9c6bc7b04 100644
--- a/src/man/kinit.man
+++ b/src/man/kinit.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KINIT" "1" " " "1.21.1" "MIT Kerberos"
+.TH "KINIT" "1" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kinit \- obtain and cache Kerberos ticket-granting ticket
 .
diff --git a/src/man/klist.man b/src/man/klist.man
index 186fb8dd6..beb7932e2 100644
--- a/src/man/klist.man
+++ b/src/man/klist.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KLIST" "1" " " "1.21.1" "MIT Kerberos"
+.TH "KLIST" "1" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 klist \- list cached Kerberos tickets
 .
diff --git a/src/man/kpasswd.man b/src/man/kpasswd.man
index 240724be9..537ddc653 100644
--- a/src/man/kpasswd.man
+++ b/src/man/kpasswd.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KPASSWD" "1" " " "1.21.1" "MIT Kerberos"
+.TH "KPASSWD" "1" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kpasswd \- change a user's Kerberos password
 .
diff --git a/src/man/kprop.man b/src/man/kprop.man
index 367367802..09c053615 100644
--- a/src/man/kprop.man
+++ b/src/man/kprop.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KPROP" "8" " " "1.21.1" "MIT Kerberos"
+.TH "KPROP" "8" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kprop \- propagate a Kerberos V5 principal database to a replica server
 .
diff --git a/src/man/kpropd.man b/src/man/kpropd.man
index f173a2cf0..8cb6482bd 100644
--- a/src/man/kpropd.man
+++ b/src/man/kpropd.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KPROPD" "8" " " "1.21.1" "MIT Kerberos"
+.TH "KPROPD" "8" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kpropd \- Kerberos V5 replica KDC update server
 .
diff --git a/src/man/kproplog.man b/src/man/kproplog.man
index b4b6773bb..b6a0caf1b 100644
--- a/src/man/kproplog.man
+++ b/src/man/kproplog.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KPROPLOG" "8" " " "1.21.1" "MIT Kerberos"
+.TH "KPROPLOG" "8" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kproplog \- display the contents of the Kerberos principal update log
 .
diff --git a/src/man/krb5-config.man b/src/man/krb5-config.man
index 7dc632f11..5ac268b72 100644
--- a/src/man/krb5-config.man
+++ b/src/man/krb5-config.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KRB5-CONFIG" "1" " " "1.21.1" "MIT Kerberos"
+.TH "KRB5-CONFIG" "1" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 krb5-config \- tool for linking against MIT Kerberos libraries
 .
diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man
index 4e8773288..644496a5a 100644
--- a/src/man/krb5.conf.man
+++ b/src/man/krb5.conf.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KRB5.CONF" "5" " " "1.21.1" "MIT Kerberos"
+.TH "KRB5.CONF" "5" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 krb5.conf \- Kerberos configuration file
 .
diff --git a/src/man/krb5kdc.man b/src/man/krb5kdc.man
index 41b280049..d61d0bbdf 100644
--- a/src/man/krb5kdc.man
+++ b/src/man/krb5kdc.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KRB5KDC" "8" " " "1.21.1" "MIT Kerberos"
+.TH "KRB5KDC" "8" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 krb5kdc \- Kerberos V5 KDC
 .
diff --git a/src/man/ksu.man b/src/man/ksu.man
index b322d0582..121a2b5af 100644
--- a/src/man/ksu.man
+++ b/src/man/ksu.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KSU" "1" " " "1.21.1" "MIT Kerberos"
+.TH "KSU" "1" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 ksu \- Kerberized super-user
 .
diff --git a/src/man/kswitch.man b/src/man/kswitch.man
index 6d11578ed..e7ff8c20f 100644
--- a/src/man/kswitch.man
+++ b/src/man/kswitch.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KSWITCH" "1" " " "1.21.1" "MIT Kerberos"
+.TH "KSWITCH" "1" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kswitch \- switch primary ticket cache
 .
diff --git a/src/man/ktutil.man b/src/man/ktutil.man
index c78705ce3..f621068fa 100644
--- a/src/man/ktutil.man
+++ b/src/man/ktutil.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KTUTIL" "1" " " "1.21.1" "MIT Kerberos"
+.TH "KTUTIL" "1" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 ktutil \- Kerberos keytab file maintenance utility
 .
diff --git a/src/man/kvno.man b/src/man/kvno.man
index 0bbcb07f0..15c840d7e 100644
--- a/src/man/kvno.man
+++ b/src/man/kvno.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "KVNO" "1" " " "1.21.1" "MIT Kerberos"
+.TH "KVNO" "1" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 kvno \- print key version numbers of Kerberos principals
 .
diff --git a/src/man/sclient.man b/src/man/sclient.man
index e58788dc0..5aef2f979 100644
--- a/src/man/sclient.man
+++ b/src/man/sclient.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "SCLIENT" "1" " " "1.21.1" "MIT Kerberos"
+.TH "SCLIENT" "1" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 sclient \- sample Kerberos version 5 client
 .
diff --git a/src/man/sserver.man b/src/man/sserver.man
index 95532b522..68e7caa1a 100644
--- a/src/man/sserver.man
+++ b/src/man/sserver.man
@@ -1,6 +1,6 @@
 .\" Man page generated from reStructuredText.
 .
-.TH "SSERVER" "8" " " "1.21.1" "MIT Kerberos"
+.TH "SSERVER" "8" " " "1.21.2" "MIT Kerberos"
 .SH NAME
 sserver \- sample Kerberos version 5 server
 .
diff --git a/src/patchlevel.h b/src/patchlevel.h
index 9afd98506..b47e4e949 100644
--- a/src/patchlevel.h
+++ b/src/patchlevel.h
@@ -51,7 +51,7 @@
  */
 #define KRB5_MAJOR_RELEASE 1
 #define KRB5_MINOR_RELEASE 21
-#define KRB5_PATCHLEVEL 1
-#define KRB5_RELTAIL "postrelease"
+#define KRB5_PATCHLEVEL 2
+/* #undef KRB5_RELTAIL */
 /* #undef KRB5_RELDATE */
-#define KRB5_RELTAG "krb5-1.21"
+#define KRB5_RELTAG "krb5-1.21.2-final"
diff --git a/src/po/mit-krb5.pot b/src/po/mit-krb5.pot
index 253d6a391..77263f4c3 100644
--- a/src/po/mit-krb5.pot
+++ b/src/po/mit-krb5.pot
@@ -6,9 +6,9 @@
 #, fuzzy
 msgid ""
 msgstr ""
-"Project-Id-Version: mit-krb5 1.21.1\n"
+"Project-Id-Version: mit-krb5 1.21.2\n"
 "Report-Msgid-Bugs-To: \n"
-"POT-Creation-Date: 2023-07-10 16:43-0400\n"
+"POT-Creation-Date: 2023-08-14 02:19-0400\n"
 "PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n"
 "Last-Translator: FULL NAME <EMAIL at ADDRESS>\n"
 "Language-Team: LANGUAGE <LL at li.org>\n"
@@ -3467,7 +3467,7 @@ msgstr ""
 msgid "not checking transit path"
 msgstr ""
 
-#: ../../src/kdc/do_tgs_req.c:1044
+#: ../../src/kdc/do_tgs_req.c:1045
 #, c-format
 msgid "TGS_REQ : handle_authdata (%d)"
 msgstr ""


More information about the cvs-krb5 mailing list