CVE-2026-40356: CVE-2026-40355, CVE-2026-40356: MIT krb5 1.18+ Unauthenticated Network ad overrun and null pointer defence
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40356?
CVE-2026-40356 is classified as a high-severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2026-40356?
To fix CVE-2026-40356, upgrade MIT krb5 to version 1.22.3 or later.
What are the risks associated with CVE-2026-40356?
The risks associated with CVE-2026-40356 include unauthorized access and potential system crashes due to integer underflow issues.
Which versions of MIT krb5 are affected by CVE-2026-40356?
CVE-2026-40356 affects MIT krb5 versions prior to 1.22.3, specifically from version 1.18 onwards.
Is user authentication required to exploit CVE-2026-40356?
No, user authentication is not required to exploit CVE-2026-40356, making it particularly dangerous.