{"id":"CVE-2026-40356","details":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.","modified":"2026-07-14T17:48:17.984336Z","published":"2026-04-28T00:00:00Z","related":["ALSA-2026:16799","ALSA-2026:19145","ALSA-2026:19357","SUSE-SU-2026:1816-1","SUSE-SU-2026:21618-1","SUSE-SU-2026:21629-1","SUSE-SU-2026:22255-1","SUSE-SU-2026:22322-1","SUSE-SU-2026:2449-1","SUSE-SU-2026:2848-1","openSUSE-SU-2026:10729-1","openSUSE-SU-2026:21021-1"],"database_specific":{"cna_assigner":"mitre","cwe_ids":["CWE-191"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40356.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.18"},{"fixed":"1.22.3"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"introduced":"1.18"},{"fixed":"1.22.3"}],"source":"CPE_FIELD"},{"extracted_events":[{"fixed":"1.22.3"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40356.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40356"},{"type":"ADVISORY","url":"https://web.mit.edu/kerberos/advisories/"},{"type":"FIX","url":"https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/krb5/krb5","events":[{"introduced":"0"},{"fixed":"2e75f0d9362fb979f5fc92829431a590a130929f"}],"database_specific":{"cpe":"cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.18.0"},{"last_affected":"1.22.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-40356.json","vanir_signatures_modified":"2026-07-14T17:48:17Z","vanir_signatures":[{"target":{"file":"src/lib/gssapi/spnego/negoex_util.c","function":"parse_nego_message"},"deprecated":false,"digest":{"function_hash":"142762992336514430865573446923858023953","length":1059},"id":"CVE-2026-40356-0d8c4b90","signature_type":"Function","signature_version":"v1","source":"https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f"},{"deprecated":false,"digest":{"line_hashes":["40952602198558450187255405215139956686","188683493495594530274596671268481475985","166540009649839522164965351439044043758","38887152117437256870742115587696304902","211427320194663522795255588816265163872","157791089749722385199311103137710402737","175049674007297452272386585316915970498","125706769889133001570824185629183380644"],"threshold":0.9},"id":"CVE-2026-40356-575ea1f8","signature_type":"Line","signature_version":"v1","source":"https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","target":{"file":"src/lib/gssapi/spnego/negoex_util.c"}},{"digest":{"function_hash":"250685795234022013172144621242627026091","length":1843},"id":"CVE-2026-40356-e36857fc","signature_type":"Function","signature_version":"v1","source":"https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","target":{"file":"src/lib/gssapi/spnego/negoex_util.c","function":"parse_message"},"deprecated":false}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}