Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40356

Опубликовано: 28 апр. 2026
Источник: redhat
CVSS3: 5.9

Описание

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.

A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit an integer underflow and an out-of-bounds read vulnerability by calling gss_accept_sec_context() on a system with a NegoEx mechanism registered. This can lead to the process terminating, resulting in a Denial of Service (DoS).

Отчет

This Moderate impact denial of service flaw in MIT Kerberos 5 (krb5) allows an unauthenticated remote attacker to trigger an integer underflow and out-of-bounds read. This vulnerability, which can lead to process termination, specifically affects systems where the NegoEx mechanism is registered and gss_accept_sec_context() is called. While Kerberos is a fundamental service, the prerequisite of a registered NegoEx mechanism limits the attack surface.

Меры по смягчению последствий

To mitigate this issue, ensure that the NegoEx mechanism is not registered in the /etc/gss/mech configuration file. Removing the corresponding entry from this file will prevent the vulnerable code path from being activated. This action may impact services that rely on the NegoEx GSS-API mechanism. A restart of affected Kerberos-dependent services may be required for the change to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6krb5Fix deferred
Red Hat Enterprise Linux 7krb5Fix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10krb5FixedRHSA-2026:1914519.05.2026
Red Hat Enterprise Linux 8krb5FixedRHSA-2026:1679913.05.2026
Red Hat Enterprise Linux 9krb5FixedRHSA-2026:1935719.05.2026
Red Hat Enterprise Linux 9krb5FixedRHSA-2026:1935719.05.2026
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionskrb5FixedRHSA-2026:2468509.06.2026
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutionskrb5FixedRHSA-2026:2468609.06.2026
Red Hat Enterprise Linux 9.6 Extended Update Supportkrb5FixedRHSA-2026:2468309.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-191
https://bugzilla.redhat.com/show_bug.cgi?id=2463368krb5: MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 месяца назад

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.

CVSS3: 5.9
nvd
3 месяца назад

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.

CVSS3: 5.9
msrc
3 месяца назад

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.

CVSS3: 5.9
debian
3 месяца назад

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underf ...

CVSS3: 5.9
github
3 месяца назад

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.

5.9 Medium

CVSS3