PT-2026-35656 · Mit+3 · Mit Kerberos 5+3

·

CVE-2026-40355

·

Published

2026-04-13

·

Updated

2026-08-12

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 versions prior to 1.22.3
Description A NULL pointer dereference occurs when an application calls the gss accept sec context() function on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this condition, leading to process termination within the parse nego message() function.
Recommendations Update to version 1.22.3 or later.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:16799
ALSA-2026:19145
ALSA-2026:19357
AZL-85235
BDU:2026-12847
CVE-2026-40355
ECHO-3921-9F59-F2E1
JLSEC-2026-1258
OESA-2026-2257
OPENSUSE-SU-2026:10729-1
OPENSUSE-SU-2026:21021-1
RHSA-2026:12220
RHSA-2026:16799
RHSA-2026:19145
RHSA-2026:19357
SUSE-SU-2026:1816-1
SUSE-SU-2026:21618-1
SUSE-SU-2026:21629-1
SUSE-SU-2026:22255-1
SUSE-SU-2026:22322-1
SUSE-SU-2026:2449-1
SUSE-SU-2026:2848-1
USN-8585-1

Affected Products

Linuxmint
Mit Kerberos 5
Rocky Linux
Ubuntu