Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91926

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 3.7

Описание

A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not free the previous allocation when the same AV_PAIR type appears more than once, leaking the earlier allocation. A malicious or man-in-the-middle server can exploit this to cause gradual memory exhaustion on the client during NTLM authentication, leading to a denial of service.

Отчет

This vulnerability is rated as Low severity because exploitation requires the attacker to control or impersonate the NTLM server (or hold a man-in-the-middle position), and the resulting memory leak is bounded and gradual, requiring sustained repeated authentications to produce meaningful resource exhaustion. The vulnerability only affects the NTLM client (initiator) path; the server (acceptor) path is not affected. Red Hat Enterprise Linux 8 ships gssntlmssp and is affected. gssntlmssp was removed from RHEL 9 and later releases, so those products are not affected.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8gssntlmsspFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2533698gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicated AV_PAIR entries in NTLM CHALLENGE

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
3 дня назад

(A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM targ ...)

CVSS3: 3.7
nvd
4 дня назад

A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not free the previous allocation when the same AV_PAIR type appears more than once, leaking the earlier allocation. A malicious or man-in-the-middle server can exploit this to cause gradual memory exhaustion on the client during NTLM authentication, leading to a denial of service.

CVSS3: 3.7
debian
4 дня назад

A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM targ ...

CVSS3: 3.7
github
4 дня назад

A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not free the previous allocation when the same AV_PAIR type appears more than once, leaking the earlier allocation. A malicious or man-in-the-middle server can exploit this to cause gradual memory exhaustion on the client during NTLM authentication, leading to a denial of service.

3.7 Low

CVSS3