CVE-2026-40355

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-28 06:16

Updated : 2026-07-14 13:18


NVD link : CVE-2026-40355

Mitre link : CVE-2026-40355

CVE.ORG link : CVE-2026-40355


JSON object : View

Products Affected

mit

  • kerberos_5
CWE
CWE-476

NULL Pointer Dereference