Back

HIGH

krb5: MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism

Published Apr 28, 2026

Description

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.

Affected products

Remediation

Red Hat statement

Moderate: This flaw allows an unauthenticated remote attacker to cause a Denial of Service in MIT Kerberos 5 by triggering a NULL pointer dereference. Exploitation requires the NegoEx mechanism to be explicitly registered in the system's GSSAPI configuration, which is not a default state in all Red Hat environments.

Red Hat mitigation

To mitigate this issue, remove the NegoEx mechanism registration from the system's GSSAPI configuration if it is not required. This can typically be achieved by removing or commenting out the relevant entry in `/etc/gss/mech`. A restart of services utilizing Kerberos might be necessary for the changes to take effect, which could impact Kerberos-dependent functionality.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Apr 28, 2026
Updated Sep 8, 2026
Reserved Apr 11, 2026

CISA Vulnrichment

Updated Apr 28, 2026

NVD

Status Modified
Modified Jul 14, 2026

Red Hat

Severity Moderate
Public date Apr 28, 2026
Bugzilla 2463370

ENISA EUVD

Assigner mitre
Published Apr 28, 2026
Updated Sep 8, 2026

GitHub

No data