Bug 2463370 (CVE-2026-40355) - CVE-2026-40355 krb5: MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism
Summary: CVE-2026-40355 krb5: MIT Kerberos 5: Denial of Service via NULL pointer deref...
Keywords:
Status: NEW
Alias: CVE-2026-40355
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2463393 2463394 2463398
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-28 07:02 UTC by OSIDB Bzimport
Modified: 2026-06-10 13:36 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2026:16994 0 None None None 2026-05-13 10:42:00 UTC
Red Hat Product Errata RHBA-2026:16996 0 None None None 2026-05-13 10:57:58 UTC
Red Hat Product Errata RHBA-2026:16998 0 None None None 2026-05-13 11:38:29 UTC
Red Hat Product Errata RHBA-2026:17049 0 None None None 2026-05-13 13:39:13 UTC
Red Hat Product Errata RHBA-2026:17057 0 None None None 2026-05-13 13:44:37 UTC
Red Hat Product Errata RHBA-2026:18060 0 None None None 2026-05-19 11:18:44 UTC
Red Hat Product Errata RHBA-2026:18061 0 None None None 2026-05-18 12:13:41 UTC
Red Hat Product Errata RHBA-2026:18066 0 None None None 2026-05-18 13:43:07 UTC
Red Hat Product Errata RHBA-2026:18067 0 None None None 2026-05-18 14:25:58 UTC
Red Hat Product Errata RHBA-2026:19543 0 None None None 2026-05-20 07:27:31 UTC
Red Hat Product Errata RHBA-2026:19679 0 None None None 2026-05-20 13:23:21 UTC
Red Hat Product Errata RHSA-2026:16799 0 None None None 2026-05-13 05:45:31 UTC
Red Hat Product Errata RHSA-2026:19145 0 None None None 2026-05-19 16:09:38 UTC
Red Hat Product Errata RHSA-2026:19357 0 None None None 2026-05-19 21:40:06 UTC

Description OSIDB Bzimport 2026-04-28 07:02:08 UTC
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.

Comment 4 errata-xmlrpc 2026-05-13 05:45:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:16799 https://access.redhat.com/errata/RHSA-2026:16799

Comment 5 errata-xmlrpc 2026-05-19 16:09:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:19145 https://access.redhat.com/errata/RHSA-2026:19145

Comment 6 errata-xmlrpc 2026-05-19 21:40:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:19357 https://access.redhat.com/errata/RHSA-2026:19357


Note You need to log in before you can comment on or make changes to this bug.