Debian alert DLA-4603-1 (krb5)
| From: | Emmanuel Arias <eamanu@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4603-1] krb5 security update | |
| Date: | Thu, 28 May 2026 08:35:55 -0300 | |
| Message-ID: | <ahgomzUF9osNXCYk@debian> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4603-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Emmanuel Arias May 28, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : krb5 Version : 1.18.3-6+deb11u8 CVE ID : CVE-2026-40355 CVE-2026-40356 Debian Bug : 1135317 Two vulnerabilities was found in krb5, the MIT implementation of Kerberos, that an unauthenticated remote attacker can take advantage of these vulnerabilities to cause a denial of service. CVE-2026-40355 If an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech, an unauthenticated remote attacker can trigger a null pointer dereference, causing the process to terminate. CVE-2026-40356 If an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech, an unauthenticated remote attacker can trigger a read overrun of up to 52 bytes, possibly causing the process to terminate. Exfiltration of the bytes read does not appear possible. For Debian 11 bullseye, these problems have been fixed in version 1.18.3-6+deb11u8. We recommend that you upgrade your krb5 packages. For the detailed security status of krb5 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/krb5 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEE3lnVbvHK7ir4q61+p3sXeEcY/EFAmoYKJoACgkQ+p3sXeEc Y/H0YQ//Wr2SuQWl/PK3+WmNXgYAJHB/5utfhcT3WFf1tAx3AtZA8yemAcHdQFGk 6WazN5XKmqv6UdS6vFBHujJJtu630uOjwqpd1DCvnDI7xImCLgMDcPBDiLfKTolO CSNWva40GAB1khGLbsZ0+pbQBTiqenwMEXrxt4UlbFWPLixu2psuEGmbUold+p1n 3EOYwRS3Wj1BALPjaA38UdT9xWH/r8/WfJyusPKG8tM+V1SOZ8xFkphaeJChmLzJ fPUs5PPZ+DKLBJ637OA5l7rvkRvKPYtiAy4O69E0Ddk/P+F0sgNZglv3nwDNQA0c C4ky1N0OkvQzZP2bks+IAtg4aI+pVf94eyeV9sSwbzHB8bf6UhhzRZ7eTYPqnhd0 +K4gfevleDeSFFtoljbcfD5i2uqhxnITIkkMW5SVTfYCWwDIWGmBwhJec9hjrJm9 l/b7YxkfXDhb/SfQoVzINfsx7v12k6KTWr+6sIVhV7nvDW5Gn7YVwCH1XGiVYf37 PWcKEqZH+CJiOaH1+RGK1HSgob68qH6M1w6HunxtJ/OymO3Uoy8QLDlUP4yeSxY9 jEWkuPoS+/p186TRKJB+pSZ+N9QHZjWw7ZhI+z9ipAbtZaCM2hpta4a9hiMF6MzS 7RE5yGASvwzK2Whikc+2As04Zg/JI+eKTKNcYmepuqEY0Ln7qD4= =E/2L -----END PGP SIGNATURE-----
