krb5: MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism
Published Apr 28, 2026
7.5
HIGHCVSS 3.1
EPSS 0.79%
Description
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.
Affected products
-
Affected
- ≥ 1.18, < 1.22.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| MIT | Kerberos 5 | unaffected | Affected
|
- ≥ 1.18.0 · ≤ 1.22.2
No data.
Red Hat Discovery 2
discovery/discovery-server-rhel9:1782159791
Fixed · RHSA-2026:29197
Red Hat Discovery 2
discovery/discovery-ui-rhel9:1782166952
Fixed · RHSA-2026:29197
Red Hat Enterprise Linux 10
krb5-0:1.21.3-10.el10_2
Fixed · RHSA-2026:19145
Red Hat Enterprise Linux 8
krb5-0:1.18.2-34.el8_10
Fixed · RHSA-2026:16799
Red Hat Enterprise Linux 9
krb5-0:1.21.1-10.el9_8
Fixed · RHSA-2026:19357
Red Hat Enterprise Linux 9
krb5-0:1.21.1-10.el9_8
Fixed · RHSA-2026:19357
Red Hat Hardened Images
krb5-main-1.22.2-7.hum1
Fixed · RHSA-2026:12220
Red Hat Insights proxy 1.5
insights-proxy/insights-proxy-container-rhel9:1780420428
Fixed · RHSA-2026:22634
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-tp-rhel9:1787241211
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/cds-rhel9:1779798159
Fixed · RHSA-2026:21275
Red Hat Update Infrastructure 5
rhui5/haproxy-rhel9:1779798164
Fixed · RHSA-2026:21275
Red Hat Update Infrastructure 5
rhui5/installer-rhel9:1779798165
Fixed · RHSA-2026:21275
Red Hat Update Infrastructure 5
rhui5/installer-tp-rhel9:1787135742
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1779798222
Fixed · RHSA-2026:21275
Red Hat Update Infrastructure 5
rhui5/rhua-tp-rhel9:1787241260
Fixed · RHSA-2026:58981
Red Hat Enterprise Linux 6
krb5
Fix deferred
Red Hat Enterprise Linux 7
krb5
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-hypershift-rhel9
Under investigation
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Discovery 2 | discovery/discovery-server-rhel9:1782159791 | Fixed | RHSA-2026:29197 |
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9:1782166952 | Fixed | RHSA-2026:29197 |
| Red Hat Enterprise Linux 10 | krb5-0:1.21.3-10.el10_2 | Fixed | RHSA-2026:19145 |
| Red Hat Enterprise Linux 8 | krb5-0:1.18.2-34.el8_10 | Fixed | RHSA-2026:16799 |
| Red Hat Enterprise Linux 9 | krb5-0:1.21.1-10.el9_8 | Fixed | RHSA-2026:19357 |
| Red Hat Enterprise Linux 9 | krb5-0:1.21.1-10.el9_8 | Fixed | RHSA-2026:19357 |
| Red Hat Hardened Images | krb5-main-1.22.2-7.hum1 | Fixed | RHSA-2026:12220 |
| Red Hat Insights proxy 1.5 | insights-proxy/insights-proxy-container-rhel9:1780420428 | Fixed | RHSA-2026:22634 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-tp-rhel9:1787241211 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/cds-rhel9:1779798159 | Fixed | RHSA-2026:21275 |
| Red Hat Update Infrastructure 5 | rhui5/haproxy-rhel9:1779798164 | Fixed | RHSA-2026:21275 |
| Red Hat Update Infrastructure 5 | rhui5/installer-rhel9:1779798165 | Fixed | RHSA-2026:21275 |
| Red Hat Update Infrastructure 5 | rhui5/installer-tp-rhel9:1787135742 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1779798222 | Fixed | RHSA-2026:21275 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-tp-rhel9:1787241260 | Fixed | RHSA-2026:58981 |
| Red Hat Enterprise Linux 6 | krb5 | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | krb5 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-hypershift-rhel9 | Under investigation | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Moderate: This flaw allows an unauthenticated remote attacker to cause a Denial of Service in MIT Kerberos 5 by triggering a NULL pointer dereference. Exploitation requires the NegoEx mechanism to be explicitly registered in the system's GSSAPI configuration, which is not a default state in all Red Hat environments.
Red Hat mitigation
To mitigate this issue, remove the NegoEx mechanism registration from the system's GSSAPI configuration if it is not required. This can typically be achieved by removing or commenting out the relevant entry in `/etc/gss/mech`. A restart of services utilizing Kerberos might be necessary for the changes to take effect, which could impact Kerberos-dependent functionality.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-40355 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2463370 Issue Tracking
- https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html exploitPatchThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25981 Advisory
- https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f Patch
- https://nvd.nist.gov/vuln/detail/CVE-2026-40355
- https://web.mit.edu/kerberos/advisories/ Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-40355
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data