CVE Vulnerabilities

CVE-2026-40355

NULL Pointer Dereference

Published: Apr 28, 2026 | Modified: Apr 28, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatkrb5-0:1.21.3-10.el10_2*
Red Hat Enterprise Linux 8RedHatkrb5-0:1.18.2-34.el8_10*
Red Hat Enterprise Linux 9RedHatkrb5-0:1.21.1-10.el9_8*
Red Hat Enterprise Linux 9RedHatkrb5-0:1.21.1-10.el9_8*
Red Hat Hardened ImagesRedHatkrb5-main-1.22.2-7.hum1*
Red Hat Insights proxy 1.5RedHatinsights-proxy/insights-proxy-container-rhel9:1780420428*
Red Hat Update Infrastructure 5RedHatrhui5/cds-rhel9:1779798159*
Red Hat Update Infrastructure 5RedHatrhui5/haproxy-rhel9:1779798164*
Red Hat Update Infrastructure 5RedHatrhui5/installer-rhel9:1779798165*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:1779798222*
Krb5Ubuntuesm-infra/xenial*

Potential Mitigations

References