PT-2026-51567 · Gnu · Gnu Sasl

·

CVE-2026-56968

·

Published

2026-06-23

·

Updated

2026-08-20

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU SASL versions prior to 2.2.4
Description The NTLM client lacks sanitization of a short challenge within the gsasl ntlm client step() function. This flaw allows a crafted server to cause memory disclosure.
Recommendations Update to version 2.2.4 or later.

Fix

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56968
OESA-2026-3372
OESA-2026-3373
OESA-2026-3374
OESA-2026-3375
OESA-2026-3443
OPENSUSE-SU-2026:21303-1
SUSE-SU-2026:22631-1

Affected Products

Gnu Sasl