Debian Package Tracker
Register | Log in
Subscribe

krb5

Choose email to subscribe with

general
  • source: krb5 (main)
  • version: 1.22.1-3
  • maintainer: Sam Hartman (DMD)
  • uploaders: Russ Allbery [DMD] – Benjamin Kaduk [DMD]
  • arch: all any
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.18.3-6+deb11u5
  • o-o-sec: 1.18.3-6+deb11u8
  • o-o-p-u: 1.18.3-6+deb11u5
  • oldstable: 1.20.1-2+deb12u4
  • old-sec: 1.20.1-2+deb12u5
  • old-p-u: 1.20.1-2+deb12u5
  • stable: 1.21.3-5
  • stable-sec: 1.21.3-5+deb13u1
  • stable-p-u: 1.21.3-5+deb13u1
  • testing: 1.22.1-2.1
  • unstable: 1.22.1-3
versioned links
  • 1.18.3-6+deb11u5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.18.3-6+deb11u8: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.20.1-2+deb12u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.20.1-2+deb12u5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.21.3-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.21.3-5+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.22.1-2.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.22.1-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • krb5-admin-server (5 bugs: 0, 4, 1, 0)
  • krb5-doc (2 bugs: 0, 1, 1, 0)
  • krb5-gss-samples
  • krb5-k5tls
  • krb5-kdc
  • krb5-kdc-ldap (1 bugs: 0, 1, 0, 0)
  • krb5-kpropd
  • krb5-locales (1 bugs: 0, 1, 0, 0)
  • krb5-multidev (1 bugs: 0, 0, 1, 0)
  • krb5-otp
  • krb5-pkinit
  • krb5-user (3 bugs: 0, 1, 2, 0)
  • libgssapi-krb5-2 (3 bugs: 0, 3, 0, 0)
  • libgssrpc4t64
  • libk5crypto3 (1 bugs: 0, 1, 0, 0)
  • libkadm5clnt-mit12
  • libkadm5srv-mit12
  • libkdb5-10t64
  • libkrad-dev
  • libkrad0
  • libkrb5-3 (3 bugs: 0, 2, 1, 0)
  • libkrb5-dbg
  • libkrb5-dev (2 bugs: 0, 1, 1, 0)
  • libkrb5support0 (1 bugs: 0, 1, 0, 0)
action needed
A new upstream version is available: 1.22.2 high
A new upstream version 1.22.2 is available, you should consider packaging it.
Created: 2026-02-02 Last update: 2026-06-21 03:31
lintian reports 62 warnings high
Lintian reports 62 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2024-07-06 Last update: 2026-06-20 02:00
5 security issues in buster high

There are 5 open security issues in buster.

2 important issues:
  • CVE-2024-37370: In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.
  • CVE-2024-37371: In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
3 issues postponed or untriaged:
  • CVE-2024-26458: (needs triaging) Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
  • CVE-2024-26461: (needs triaging) Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
  • CVE-2024-26462: (needs triaging) Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.
Created: 2024-06-27 Last update: 2024-06-29 05:38
3 bugs tagged patch in the BTS normal
The BTS contains patches fixing 3 bugs, consider including or untagging them.
Created: 2026-06-02 Last update: 2026-06-21 03:30
1 open merge request in Salsa normal
There is 1 open merge request for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2026-03-07 Last update: 2026-03-07 12:00
debian/patches: 16 patches to forward upstream low

Among the 16 debian patches available in version 1.22.1-3 of the package, we noticed the following issues:

  • 16 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-06-20 12:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.0).
Created: 2025-02-21 Last update: 2026-06-19 22:31
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • excuses:
    • Migration status for krb5 (1.22.1-2.1 to 1.22.1-3): BLOCKED: Maybe temporary, maybe blocked but Britney is missing information (check below)
    • Issues preventing migration:
    • ∙ ∙ Missing build on riscv64
    • ∙ ∙ Autopkgtest deferred on riscv64: missing arch:riscv64 build
    • ∙ ∙ Autopkgtest for audit/1:4.1.2-1: amd64: No tests, superficial or marked flaky ♻, arm64: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻ (reference ♻), loong64: No tests, superficial or marked flaky ♻ (reference ♻), ppc64el: No tests, superficial or marked flaky ♻ (reference ♻), s390x: Test triggered
    • ∙ ∙ Autopkgtest for balsa/2.6.5-3: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for bind9/1:9.20.23-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for cccolutils/1.5-4: amd64: No tests, superficial or marked flaky ♻, arm64: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻ (reference ♻), loong64: No tests, superficial or marked flaky ♻ (reference ♻), ppc64el: No tests, superficial or marked flaky ♻ (reference ♻), s390x: Test triggered
    • ∙ ∙ Autopkgtest for cockpit/362-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for cups/2.4.18-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for curl/8.20.0-5: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for cyrus-imapd/3.12.2-1: amd64: Pass, arm64: Test triggered (failure will be ignored), i386: Failed (not a regression) ♻ (reference ♻), loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for cyrus-sasl2/2.1.28+dfsg1-11: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for dovecot/1:2.4.4+dfsg1-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for elinks/0.19.1-2: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for evolution-data-server/3.56.2-8: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for fetchmail/6.6.3-3: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for freeradius/3.2.8+dfsg-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for freerdp3/3.26.0+dfsg-1: amd64: Pass ♻ (reference ♻), arm64: Pass ♻ (reference ♻), i386: Pass ♻ (reference ♻), loong64: Failed (not a regression) ♻ (reference ♻), ppc64el: Pass ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for freerdp3: s390x: Test triggered
    • ∙ ∙ Autopkgtest for freetds/1.5.5+ds-1: amd64: No tests, superficial or marked flaky ♻, arm64: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻ (reference ♻), loong64: No tests, superficial or marked flaky ♻ (reference ♻), ppc64el: No tests, superficial or marked flaky ♻ (reference ♻), s390x: Test triggered
    • ∙ ∙ Autopkgtest for gnome-online-accounts/3.58.1-1: amd64: No tests, superficial or marked flaky ♻, arm64: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻ (reference ♻), loong64: No tests, superficial or marked flaky ♻ (reference ♻), ppc64el: No tests, superficial or marked flaky ♻ (reference ♻), s390x: Test triggered
    • ∙ ∙ Autopkgtest for gnome-remote-desktop/50.1-5: amd64: Pass, arm64: Pass, i386: No tests, superficial or marked flaky ♻ (reference ♻), loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for gsasl/2.2.3-1: amd64: Pass ♻, arm64: Pass ♻ (reference ♻), i386: Failed (not a regression) ♻ (reference ♻), loong64: Pass ♻ (reference ♻), ppc64el: Pass ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for gsasl: s390x: Test triggered
    • ∙ ∙ Autopkgtest for gssproxy/0.9.2-5: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for inetutils/2:2.8-2: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for krb5/1.22.1-3: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libauthen-krb5-admin-perl/0.17-5: amd64: No tests, superficial or marked flaky ♻, arm64: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻ (reference ♻), loong64: No tests, superficial or marked flaky ♻ (reference ♻), ppc64el: No tests, superficial or marked flaky ♻ (reference ♻), s390x: Test triggered
    • ∙ ∙ Autopkgtest for libauthen-krb5-perl/1.906-2: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libauthen-krb5-simple-perl/0.43-3: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libgit2/1.9.4+ds-1: amd64: No tests, superficial or marked flaky ♻, arm64: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻ (reference ♻), loong64: No tests, superficial or marked flaky ♻ (reference ♻), ppc64el: No tests, superficial or marked flaky ♻ (reference ♻), s390x: Test triggered
    • ∙ ∙ Autopkgtest for libgssapi-perl/0.28-4: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libgssglue/0.9-2: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libreoffice/4:26.2.4.2-1: amd64: Pass, arm64: Test triggered (failure will be ignored), i386: Test triggered (failure will be ignored), loong64: Failed (not a regression) ♻ (reference ♻), ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libsoup3/3.6.6-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered (failure will be ignored)
    • ∙ ∙ Autopkgtest for libssh/0.12.0-3: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libtirpc/1.3.7+ds-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for lighttpd/1.4.84-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for mariadb/1:11.8.6-6: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for netatalk/4.5.0~ds-3: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for nfs-utils/1:2.9.1-1: amd64: Pass, arm64: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻ (reference ♻), loong64: No tests, superficial or marked flaky ♻ (reference ♻), ppc64el: No tests, superficial or marked flaky ♻ (reference ♻), s390x: Test triggered
    • ∙ ∙ Autopkgtest for nss-pam-ldapd/0.9.13-2: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for ocserv: amd64: Test triggered, arm64: Test triggered, i386: Test triggered, loong64: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for openssh/1:10.3p1-4: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for pdns/5.1.1-2: amd64: Pass, arm64: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for postgresql-18/18.4-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for pymssql/2.3.10-2: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for python-bonsai/1.5.3+ds-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for remctl/3.18-5: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for rsyslog/8.2604.0-4: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for ruby-gssapi/1.3.1-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for ruby-timfel-krb5-auth/0.8.3-3: amd64: No tests, superficial or marked flaky ♻, arm64: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻ (reference ♻), loong64: No tests, superficial or marked flaky ♻ (reference ♻), ppc64el: No tests, superficial or marked flaky ♻ (reference ♻), s390x: Test triggered
    • ∙ ∙ Autopkgtest for s-nail/14.9.25-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for serf/1.3.10-3: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for shibboleth-sp/3.5.2+dfsg-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for squid/7.6-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for wireshark/4.6.6-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for yafc/1.3.7-5: amd64: Pass, arm64: Pass, i386: Pass, loong64: No tests, superficial or marked flaky ♻ (reference ♻), ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Lintian check waiting for test results on riscv64 - info
    • ∙ ∙ Reproducibility check waiting for results on arm64 - info
    • ∙ ∙ Too young, only 1 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/k/krb5.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-06-19] Accepted krb5 1.22.1-3 (source) into unstable (Sam Hartman)
  • [2026-05-27] Accepted krb5 1.18.3-6+deb11u8 (source) into oldoldstable-security (Emmanuel Arias)
  • [2026-05-23] Accepted krb5 1.21.3-5+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-05-23] Accepted krb5 1.20.1-2+deb12u5 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-05-23] krb5 1.22.1-2.1 MIGRATED to testing (Debian testing watch)
  • [2026-05-22] Accepted krb5 1.20.1-2+deb12u5 (source) into oldstable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-05-22] Accepted krb5 1.21.3-5+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-05-12] Accepted krb5 1.22.1-2.1 (source) into unstable (Salvatore Bonaccorso)
  • [2025-11-18] krb5 1.22.1-2 MIGRATED to testing (Debian testing watch)
  • [2025-11-14] Accepted krb5 1.22.1-2 (source) into unstable (Sam Hartman)
  • [2025-10-14] Accepted krb5 1.22.1-1 (source) into experimental (Sam Hartman)
  • [2025-05-31] Accepted krb5 1.20.1-2+deb12u4 (source) into proposed-updates (Debian FTP Masters) (signed by: Bastien ROUCARIÈS)
  • [2025-05-30] Accepted krb5 1.18.3-6+deb11u7 (source) into oldstable-security (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2025-04-14] Accepted krb5 1.20.1-2+deb12u3 (source) into proposed-updates (Debian FTP Masters) (signed by: Bastien ROUCARIÈS)
  • [2025-03-15] krb5 1.21.3-5 MIGRATED to testing (Debian testing watch)
  • [2025-03-13] Accepted krb5 1.21.3-5 (source) into unstable (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2025-02-23] Accepted krb5 1.18.3-6+deb11u6 (source) into oldstable-security (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2025-01-29] krb5 1.21.3-4 MIGRATED to testing (Debian testing watch)
  • [2025-01-16] Accepted krb5 1.21.3-4 (source) into unstable (Sam Hartman)
  • [2024-07-29] krb5 1.21.3-3 MIGRATED to testing (Debian testing watch)
  • [2024-07-08] Accepted krb5 1.20.1-2+deb12u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Sam Hartman)
  • [2024-07-07] Accepted krb5 1.18.3-6+deb11u5 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Sam Hartman)
  • [2024-07-05] Accepted krb5 1.18.3-6+deb11u5 (source) into oldstable-security (Debian FTP Masters) (signed by: Sam Hartman)
  • [2024-07-05] Accepted krb5 1.20.1-2+deb12u2 (source) into stable-security (Debian FTP Masters) (signed by: Sam Hartman)
  • [2024-07-05] Accepted krb5 1.21.3-3 (source) into unstable (Sam Hartman)
  • [2024-07-04] Accepted krb5 1.21.3-2 (source) into unstable (Sam Hartman)
  • [2024-06-27] Accepted krb5 1.21.3-1 (source) into unstable (Sam Hartman)
  • [2024-06-22] krb5 1.21.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-18] Accepted krb5 1.21.2-1 (source) into unstable (Sam Hartman)
  • [2024-05-03] krb5 1.20.1-6 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 33 34
  • RC: 0
  • I&N: 19 20
  • M&W: 14
  • F&P: 0
  • patch: 3
links
  • homepage
  • lintian (0, 62)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (100, 100)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.22.1-2ubuntu4
  • patches for 1.22.1-2ubuntu4

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing