Nixpkgs security tracker

Try the new UI
Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 1 week, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
crypto: krb5 - use kfree_sensitive() for derived key buffers

In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - use kfree_sensitive() for derived key buffers crypto_krb5_prepare_encryption() and crypto_krb5_prepare_checksum() free the buffer holding the freshly derived keys with plain kfree(), leaving the key material behind in the freed slab object.

Affected products

Linux
  • <731a5b6fb4c1705f9405d9029dd64ea81e336207
  • ==6.15
  • =<7.2.*
  • <a1bf79365794783b19f5b09e8a23f7ee311e8931
  • <f7d53dd3f267e46a784f219a75072f2f400d42b9
  • =<*
  • =<7.1.*
  • <6.15
  • =<6.18.*
  • <91b96dc9cc250cd16751f53de525cf3442ca0962