CVE-2026-40356: In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.
Overview
- Severity
- Medium (CVSS 5.9)
- CVSS Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U
- Exploit Status
- Not Exploited
- Patch Tuesday
- 2026-Apr
- Released
- 2026-05-01
- Last Updated
- 2026-06-03
- EPSS Score
- 0.46% (percentile: 36.4%)
Affected Products (3)
Other
- 20902-17084
- 20903-17086
- 21405-17084
Revision History
- 2026-05-01: Information published.
- 2026-05-11: Information published.
- 2026-06-03: Information published.