PT-2026-56810 · Zeek · Zeek

CVE-2026-60109

·

Published

2026-07-09

·

Updated

2026-07-13

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zeek versions prior to 8.0.9
Description A null pointer dereference exists in the Kerberos protocol analyzer. An unauthenticated remote attacker can cause the sensor to crash by sending a specially crafted KRB ERROR message with error-code 25 (KDC ERR PREAUTH REQUIRED) that includes a PA-DATA element with padata-type 2, 3, 11, or 19. The issue stems from a state mismatch between the parser and analyzer where the proc padata() function dereferences an uninitialized pa data element field. This can be triggered via a single UDP or TCP packet sent to port 88 without requiring credentials.
Recommendations Update Zeek to version 8.0.9 or later.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60109

Affected Products

Zeek