A stack-based buffer overflow vulnerability exists in the md4sum() function of libsoup’s NTLM authentication module (SoupAuthNTLM). When NTLM authentication is enabled, insufficient bounds checking on stack-allocated buffers can allow a local attacker to overwrite adjacent memory. This may result in arbitrary code execution with the privileges of the affected application. Multiple widely deployed components, including WebKit, Evolution, GVfs, and gnome-online-accounts, enable NTLM by default, increasing exposure.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:1948 https://access.redhat.com/errata/RHSA-2026:1948
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:2005 https://access.redhat.com/errata/RHSA-2026:2005
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:2006 https://access.redhat.com/errata/RHSA-2026:2006
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:2008 https://access.redhat.com/errata/RHSA-2026:2008
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:2007 https://access.redhat.com/errata/RHSA-2026:2007
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:2049 https://access.redhat.com/errata/RHSA-2026:2049
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:2182 https://access.redhat.com/errata/RHSA-2026:2182
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:2214 https://access.redhat.com/errata/RHSA-2026:2214
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:2215 https://access.redhat.com/errata/RHSA-2026:2215
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:2216 https://access.redhat.com/errata/RHSA-2026:2216
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:2396 https://access.redhat.com/errata/RHSA-2026:2396
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:2402 https://access.redhat.com/errata/RHSA-2026:2402
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:2512 https://access.redhat.com/errata/RHSA-2026:2512
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:2513 https://access.redhat.com/errata/RHSA-2026:2513
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:2514 https://access.redhat.com/errata/RHSA-2026:2514
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:2529 https://access.redhat.com/errata/RHSA-2026:2529
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:2528 https://access.redhat.com/errata/RHSA-2026:2528
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:2628 https://access.redhat.com/errata/RHSA-2026:2628