CVE-2007-3999General(mit / kerberos_5)

LOWCVSS 10.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mit kerberos_5 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kerberos_5

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 3 classified signals
  • False Positive: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-09); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
kerberos_5

12 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-09: 2Mentions · 2026-05-11: 1Mentions · 2026-05-12: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-12: 105-0905-1105-12
Signal classification2 categories
General
375.0%
False Positive
125.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-05-092
General2
2026-05-111
False Positive1
2026-05-121
General1
Full discourse4 posts
  • 関口 峻矢@NodeFlare@SekiguchiS39523
    False Positive

    Anthropicが「AI初の遠隔カーネル脆弱性発見」としてCVE-2026-4747を大々的に発表したけど、これ実は新発見じゃないっぽい。 中身を調べると、2007年にMIT Kerberosで既に発見・パッチ済みのバグ(CVE-2007-3999)と、ほぼ同じコード・ほぼ同じ修正パターン。 経緯としては、FreeBSDがMIT Kerberosの実装をコピペで持ち込んだ際に、2007年のパッチを取り込まないまま20年放置していた、というのが真相。 つまりClaude Mythosは、訓練データに入ってる20年前の脆弱性を別ファイルで再発見しただけ。「新発見」というより「既知バグの横展開探し」に近い。 AIの脆弱性発見能力を語る上で、この「訓練データ内の再発見」と「真の新発見」を区別する議論は、これからもっと重要になりそう。 https://rival.security/posts/mythos-discovered-a-cve-already-in-its-training-data---and-thats-still-worrying

    Post summary

    The article argues that CVE‑2026‑4747, announced by Anthropic, is actually a re‑discovery of the 2007 CVE‑2007‑3999, debunking the claim of a new vulnerability.

    110110514
    922 followersView on X
  • 柴田 淳-【新刊】みんなのPython第五版/Pythonで学ぶはじめてのプログラミング入門教室@ats
    General

    Anthropicの「Claude Mythos」が“AIが初めて発見・悪用したカーネルRCE脆弱性”として話題になった。しかしRival Researchの分析によると、その脆弱性(CVE-2026-4747)は、実際には2007年にMIT Kerberosで修正済みだった古い脆弱性(CVE-2007-3999)とほぼ同一だった可能性が高いという。 問題のコードは、FreeBSDのRPCSEC_GSS実装に存在する典型的なスタックバッファオーバーフローで、96バイトを超える認証情報をコピーするとスタックを書き潰してしまう。ところが、このコードはSun Microsystems時代のONC RPC/NFS実装を経由して、MIT KerberosやFreeBSDにほぼコピーされた形で残っていた。Rivalは、2007年版Kerberosの脆弱コードと2026年のFreeBSDコードを比較し、「ほぼ同一」と指摘している。 つまり、Mythosは“未知の創造的ゼロデイ”を発見したというより、「学習データに含まれていた古い脆弱性パターンを、別のコードベース上で再発見した」可能性が高い。数学分野などでLLMが既知の定理を“再発見”している議論に近く、サイバーセキュリティでも「AIの発見とは何か」という問題が浮上している。 ただし、Rivalは「だから脅威ではない」とは言っていない。むしろ重要なのは、AIが高度な創造性を持たなくても、過去の脆弱コードを大量に再発見・悪用できる点だとしている。LLMが生成するコードや設定には、訓練データ由来の古い危険パターンが混入しやすく、攻撃側AIはそれを高速に探索・悪用できる。つまり、“新しい脆弱性を作るAI”より、“過去の失敗を高速で掘り返すAI”の方が現実的脅威かもしれない。 記事の結論は、AI時代の防御では「攻撃よりも高速に検出・修正するエージェント型防御」が重要になる、というものだった。古い脆弱性でも、AIによって exploit のコストが劇的に下がる以上、防御側もAIを使わなければ不利になる、という見方である。 https://rival.security/posts/mythos-discovered-a-cve-already-in-its-training-data---and-thats-still-worrying

    Post summary

    The article analyses the claimed new CVE‑2026‑4747, concluding it is largely identical to an old, patched RCE (CVE‑2007‑3999) and provides technical details but no PoC, exploit code, or evidence of active exploitation.

    13051894
    5.9K followersView on X
  • Syukirman Amir@iamliontin
    General

    @usetraceix CVE-2007-3999

    Post summary

    The tweet merely references CVE-2007-3999 without providing any additional information.

    000717.0K
    207 followersView on X
  • Daily AI@DailyAILog
    General

    Rival Security traced the flaw to CVE-2007-3999, an identical bug in MIT Kerberos code from which the FreeBSD version was derived. This suggests Mythos acted as a high-speed pattern matcher for memorized insecure code patterns rather than exhibiting novel zero-day reasoning.

    Post summary

    The post notes that Mythos was tracking the same flaw as CVE-2007-3999 from MIT Kerberos, implying the tool identifies known insecure code patterns rather than discovering new zero‑day vulnerabilities.

    1001063
    3 followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
Appmitkerberos_51.4--
Appmitkerberos_51.4.1--
Appmitkerberos_51.4.2--
Appmitkerberos_51.4.3--
Appmitkerberos_51.4.4--
Appmitkerberos_51.5--
Appmitkerberos_51.5.1--
Appmitkerberos_51.5.2--
Appmitkerberos_51.5.3--
Appmitkerberos_51.6--
Appmitkerberos_51.6.1--
Appmitkerberos_51.6.2--

Explore more