Red Hat released updates for two Moderate-severity MIT Kerberos 5 GSS wrap-token vulnerabilities, CVE-2024-37370 and CVE-2024-37371. A network attacker able to modify a valid token in transit can alter its plaintext Extra Count field, causing the receiving application to interpret the unwrapped message as truncated. The resulting handling errors can disrupt application-layer services; CVE-2024-37370 carries a CVSS 3.1 score of 7.5 and may expose authentication-token data, while CVE-2024-37371 is rated 6.5 and is primarily assessed as an availability risk.
The fixes are delivered through Red Hat krb5 advisories including RHSA-2024:5625 for supported RHEL 8.6 ELS, AUS, telecommunications, and SAP update-service offerings, with krb5-1.18.2-16.el8_6.1, and RHSA-2024:5884 for RHEL Server AUS 8.2, with krb5-1.17-19.el8_2.1. Red Hat reported no qualifying standalone mitigation, so administrators should apply the applicable krb5 package updates across affected RHEL systems.

See affected versions and whether adversaries are exploiting it.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2024:6166 to remediate krb5 GSS message-token vulnerabilities CVE-2024-37370 and CVE-2024-37371 in Red Hat Enterprise Linux 9. The update covered applicable RHEL 9 channels across x86_64, s390x, ppc64le, and aarch64 architectures.
Red Hat updated its RHSA-2024:5625 security advisory for krb5 and the CVE-2024-37370 and CVE-2024-37371 fixes affecting RHEL 8.6 support offerings.
Red Hat issued Moderate-severity advisory RHSA-2024:5643 for RHEL 9.2 supported update channels, remediating krb5 GSS message-token vulnerabilities CVE-2024-37370 and CVE-2024-37371. The update supplied krb5-1.20.1-9.el9_2.1 packages for affected x86_64, aarch64, s390x, and ppc64le deployments.
Red Hat issued RHSA-2024:5312, fixing the two MIT Kerberos GSS message-token handling vulnerabilities, CVE-2024-37370 and CVE-2024-37371, for Red Hat Enterprise Linux 8.
Red Hat issued RHSA-2024:5316 to remediate CVE-2024-37370 and CVE-2024-37371 in krb5 for the Red Hat Enterprise Linux 7.7 Advanced Update Support stream.
Red Hat issued RHSA-2024:5076, providing a krb5 fix for CVE-2024-37370 and CVE-2024-37371 in the Red Hat Enterprise Linux 7 Extended Lifecycle Support stream.
Red Hat issued Moderate-severity advisory RHSA-2024:4743 for RHEL 8.8 extended-support channels, remediating krb5 GSS message-token flaws CVE-2024-37370 and CVE-2024-37371. The advisory provided krb5-1.18.2-26.el8_8.2 packages for affected x86_64, s390x, ppc64le, and aarch64 deployments.
Red Hat issued RHSA-2024:4734 to fix the MIT Kerberos krb5 GSS wrap-token vulnerabilities CVE-2024-37370 and CVE-2024-37371 for specified RHEL 8.4 support streams, including Advanced Mission Critical Update Support, Telecommunications Update Service, and SAP Solutions services.
Patrick Del Bello recorded CVE-2024-37371 and created Fedora tracking bug 2294680. The flaw affects krb5 versions before 1.21.3 and can cause invalid memory reads when malformed GSS message-token length fields are processed.
Red Hat documented that krb5 versions before 1.21.3 allow modification of the plaintext Extra Count field in confidential GSS krb5 wrap tokens, which can make a receiving application treat the unwrapped token as truncated. The issue was fixed upstream in krb5 commit 55fbf435edbe2e92dd8101669b1ce7144bc96fef.
Red Hat issued RHSA-2025:1673, fixing CVE-2024-37371 in the mysql:8.0 component for Red Hat Enterprise Linux 8.
Red Hat issued Moderate-severity advisory RHSA-2024:5884 for RHEL Server AUS 8.2, fixing CVE-2024-37370 and CVE-2024-37371. The advisory supplied krb5 version 1.17-19.el8_2.1 packages for x86_64 and i686 systems.
Red Hat published Moderate-severity advisory RHSA-2024:5625 to remediate CVE-2024-37370 and CVE-2024-37371 in RHEL 8.6 offerings. It supplied updated krb5 packages version 1.18.2-16.el8_6.1 for affected x86_64 and ppc64le environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
13 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.