Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40355

Опубликовано: 28 апр. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.

A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit a NULL pointer dereference vulnerability by calling gss_accept_sec_context() on a system with a NegoEx mechanism registered. This can lead to the termination of the process, resulting in a Denial of Service (DoS).

Отчет

Moderate: This flaw allows an unauthenticated remote attacker to cause a Denial of Service in MIT Kerberos 5 by triggering a NULL pointer dereference. Exploitation requires the NegoEx mechanism to be explicitly registered in the system's GSSAPI configuration, which is not a default state in all Red Hat environments.

Меры по смягчению последствий

To mitigate this issue, remove the NegoEx mechanism registration from the system's GSSAPI configuration if it is not required. This can typically be achieved by removing or commenting out the relevant entry in /etc/gss/mech. A restart of services utilizing Kerberos might be necessary for the changes to take effect, which could impact Kerberos-dependent functionality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6krb5Fix deferred
Red Hat Enterprise Linux 7krb5Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-hypershift-rhel9Under investigation
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10krb5FixedRHSA-2026:1914519.05.2026
Red Hat Enterprise Linux 8krb5FixedRHSA-2026:1679913.05.2026
Red Hat Enterprise Linux 9krb5FixedRHSA-2026:1935719.05.2026
Red Hat Enterprise Linux 9krb5FixedRHSA-2026:1935719.05.2026
Red Hat Discovery 2discovery/discovery-server-rhel9FixedRHSA-2026:2919724.06.2026
Red Hat Discovery 2discovery/discovery-ui-rhel9FixedRHSA-2026:2919724.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2463370krb5: MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism

EPSS

Процентиль: 46%
0.00611
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 месяца назад

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.

CVSS3: 5.9
nvd
3 месяца назад

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.

CVSS3: 5.9
msrc
около 2 месяцев назад

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.

CVSS3: 5.9
debian
3 месяца назад

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer de ...

CVSS3: 5.9
github
3 месяца назад

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.

EPSS

Процентиль: 46%
0.00611
Низкий

5.9 Medium

CVSS3