Описание
Security update for krb5, krb5-mini
This update for krb5, krb5-mini fixes the following issues
- CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131).
- CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366).
- CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367).
Список пакетов
Container bci/spack:latest
Container private-registry/1.2/harbor-core:latest
Container private-registry/1.2/harbor-exporter:latest
Container private-registry/1.2/harbor-jobservice:latest
Container private-registry/1.2/harbor-portal:latest
Container private-registry/1.2/harbor-registry:latest
Container private-registry/1.2/harbor-registryctl:latest
Container private-registry/1.2/harbor-trivy-adapter:latest
Container private-registry/harbor-core:latest
Container private-registry/harbor-exporter:latest
Container private-registry/harbor-jobservice:latest
Container private-registry/harbor-portal:latest
Container private-registry/harbor-registry:latest
Container private-registry/harbor-registryctl:latest
Container private-registry/harbor-trivy-adapter:latest
Container suse/kiosk/firefox-esr:latest
Container suse/kiosk/pulseaudio:latest
Container suse/kiosk/xorg-client:latest
Container suse/kiosk/xorg:latest
Container suse/ltss/sle15.6/bci-base-fips:latest
Container suse/sle15:latest
Image pr_15_7
SUSE Linux Enterprise Module for Basesystem 15 SP7
SUSE Linux Enterprise Module for Server Applications 15 SP7
SUSE Linux Enterprise Server 15 SP6-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP6
Ссылки
- Link for SUSE-SU-2026:2848-1
- E-Mail link for SUSE-SU-2026:2848-1
- SUSE Security Ratings
- SUSE Bug 1263366
- SUSE Bug 1263367
- SUSE Bug 1268131
- SUSE CVE CVE-2026-11850 page
- SUSE CVE CVE-2026-40355 page
- SUSE CVE CVE-2026-40356 page
Описание
An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.
Затронутые продукты
Ссылки
- CVE-2026-11850
- SUSE Bug 1268131
Описание
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.
Затронутые продукты
Ссылки
- CVE-2026-40355
- SUSE Bug 1263366
Описание
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.
Затронутые продукты
Ссылки
- CVE-2026-40356
- SUSE Bug 1263367