The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/dotgsreq.c via a FAST inner body that lacks a server field.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "1.18.5"
}
],
"vendor_product": "mit:kerberos_5",
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"introduced": "9.0"
},
{
"last_affected": "9.0"
}
],
"vendor_product": "debian:debian_linux",
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"introduced": "33"
},
{
"last_affected": "33"
}
],
"vendor_product": "fedoraproject:fedora",
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"introduced": "22.1.0"
},
{
"last_affected": "22.1.0"
}
],
"vendor_product": "oracle:communications_cloud_native_core_network_slice_selection_function",
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:22.1.0:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"introduced": "v8r13-14338"
},
{
"last_affected": "v8r13-14338"
}
],
"vendor_product": "starwindsoftware:starwind_virtual_san",
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:starwindsoftware:starwind_virtual_san:v8r13:14338:*:*:*:*:*:*"
]
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.18.5"
},
{
"introduced": "1.19.0"
},
{
"fixed": "1.19.3"
}
],
"cpe": "cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
]
}[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 14255.0,
"function_hash": "256313135997629940279080382534511192649"
},
"id": "CVE-2021-37750-6610d9b5",
"signature_type": "Function",
"source": "https://github.com/krb5/krb5/commit/d775c95af7606a51bf79547a94fa52ddd1cb7f49",
"target": {
"function": "process_tgs_req",
"file": "src/kdc/do_tgs_req.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"85759854495363053129708329220649920226",
"106951285823959472315379620424094599901",
"35353251504946687087079113116870528593",
"137141899296435357137104491440352983080"
]
},
"id": "CVE-2021-37750-d4305430",
"signature_type": "Line",
"source": "https://github.com/krb5/krb5/commit/d775c95af7606a51bf79547a94fa52ddd1cb7f49",
"target": {
"file": "src/kdc/do_tgs_req.c"
}
}
]
"2026-07-08T22:13:45Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-37750.json"