Debian alert DSA-6293-1 (krb5)
| From: | Salvatore Bonaccorso <carnil@debian.org> | |
| To: | debian-security-announce@lists.debian.org | |
| Subject: | [SECURITY] [DSA 6293-1] krb5 security update | |
| Date: | Fri, 22 May 2026 21:32:08 +0000 | |
| Message-ID: | <E1wQXTU-000000083zl-3n6P@seger.debian.org> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6293-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 22, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : krb5 CVE ID : CVE-2026-40355 Debian Bug : 1135317 Cem Onat Karagun discovered two vulnerabilities in the NegoEx parsing in krb5, the MIT implementation of Kerberos. An unauthenticated remote attacker can take advantage of these flaws to cause a denial of service. For the oldstable distribution (bookworm), this problem has been fixed in version 1.20.1-2+deb12u5. For the stable distribution (trixie), this problem has been fixed in version 1.21.3-5+deb13u1. We recommend that you upgrade your krb5 packages. For the detailed security status of krb5 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/krb5 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmoQyxdfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0R1Dg//cv3YDe9R/fb6MJB1sRYDv1zuNG93PZIatGHVLsW+a4MvJzuc3K+cj3d6 0m0KRSmFJOhM0ITjNyY9dfbpbu4rA6ehKkhJIPABvEY64Jdvi0EFD8HSAw6FwUQ7 SfSfwab+K+2a6oRP3v0D7JvlevKOyEjI2EseXZCAt3P8c7nkgvA+Yed/GGQZdVSS CYvIk+gtyRGuXW6YDUtWG/W+hcU/+5D4cgSHJcRSjBaFrej2nojZPkib/vv8/Hyx qDjf4tgbIwekBAFHnm/H1yvoSmh15aNaRmL7YQwYSS/tuaZJZtBYwiqTJfcWr2xt whTg/1Ut2kweMT/vfU7HT95oS2zxZAsGguPa2Widz2cC5gF06PeMv+Qfcl8xjOlk cN75c9ulR5Py7Pil672lSgBxL5yf7sbabnWyT/EFeJeWRtMzVgq7eNrStbNcdagn +TeipttfwoEZnb3habMEJefiYqK4FLQk7xOFs3oghl7/zVqlw1/6QgJ7LpH7vZV3 w45ftjP98BegvfSejC8XR9bE+1/YQbUpw1tHjjsh7Nu2VEEXfOCQ6iZCleq/O5vE TOuKujqeWi4smOVvuuHZA3upVDPHbaBPZq0DUhyLreo523Xe9eZhXJzhSVjZy663 TJcOJ1SkwdYl+HLIGzUPZ+VO32obLbN0hajXVgrdlJTx/atqND0= =nM2f -----END PGP SIGNATURE-----
