[krbdev.mit.edu #9235] git commit

Greg Hudson via RT rt-comment at krbdev.mit.edu
Fri Sep 4 19:47:57 EDT 2026


Fri Sep 04 19:47:57 2026: Request 9235 was acted upon.
 Transaction: Ticket created by ghudson at mit.edu
       Queue: krb5
     Subject: git commit
       Owner: ghudson at mit.edu
  Requestors: 
      Status: new
 Ticket <URL: https://krbdev.mit.edu/rt/Ticket/Display.html?id=9235 >



Free small client memory leak on OTP failure

When an initial credentials request using FAST OTP fails due to a
rejection from the KDC, otp_client_prep_questions() may be called
during the processing of the PREAUTH_FAILED response, due to a minor
malfunction in the preauth logic (to be fixed separately).  When this
happens the OTP challenge in the PREAUTH_FAILED padata is decoded into
modreq, overwriting and leaking the decoded challenge from the
PREAUTH_REQUIRED response.

Although we don't expect multiple otp_client_prep_questions() calls
when the preauth logic is behaving properly, it could still happen due
to unexpected KDC behavior (such as a MORE_PREAUTH_DATA_REQUIRED
response).  Fix the leak in otp_client_prep_questions() so that it
isn't admitted under any KDC behavior.

https://github.com/krb5/krb5/commit/82a4224f07ad21c2a3e977c5c4651d7d30c6f1f0
Author: Greg Hudson <ghudson at mit.edu>
Commit: 82a4224f07ad21c2a3e977c5c4651d7d30c6f1f0
Branch: master
 src/lib/krb5/krb/preauth_otp.c | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)



More information about the krb5-bugs mailing list