Описание
Security update for krb5
This update for krb5 fixes the following issues
- CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366).
- CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367).
Список пакетов
openSUSE Leap 16.0
krb5-1.21.3-160000.3.1
krb5-client-1.21.3-160000.3.1
krb5-devel-1.21.3-160000.3.1
krb5-plugin-kdb-ldap-1.21.3-160000.3.1
krb5-plugin-preauth-otp-1.21.3-160000.3.1
krb5-plugin-preauth-pkinit-1.21.3-160000.3.1
krb5-plugin-preauth-spake-1.21.3-160000.3.1
krb5-server-1.21.3-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1263366
- SUSE Bug 1263367
- SUSE CVE CVE-2026-40355 page
- SUSE CVE CVE-2026-40356 page
Описание
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.
Затронутые продукты
openSUSE Leap 16.0:krb5-1.21.3-160000.3.1
openSUSE Leap 16.0:krb5-client-1.21.3-160000.3.1
openSUSE Leap 16.0:krb5-devel-1.21.3-160000.3.1
openSUSE Leap 16.0:krb5-plugin-kdb-ldap-1.21.3-160000.3.1
Ссылки
- CVE-2026-40355
- SUSE Bug 1263366
Описание
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.
Затронутые продукты
openSUSE Leap 16.0:krb5-1.21.3-160000.3.1
openSUSE Leap 16.0:krb5-client-1.21.3-160000.3.1
openSUSE Leap 16.0:krb5-devel-1.21.3-160000.3.1
openSUSE Leap 16.0:krb5-plugin-kdb-ldap-1.21.3-160000.3.1
Ссылки
- CVE-2026-40356
- SUSE Bug 1263367