CVE-2026-40355 Details
Description
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.
A null pointer dereference vulnerability has been identified in MIT Kerberos 5 versions prior to 1.22.3. The issue arises when an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered. An unauthenticated remote attacker can exploit this vulnerability, leading to a process termination.
Users can apply the upstream patch available in commit 2e75f0d or update to a version containing the fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-019113.html | siemens-SADP | |
| https://cert-portal.siemens.com/productcert/html/ssa-082556.html | siemens-SADP | |
| https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html | CISA-ADP | ExploitPatchThird Party Advisory |
| https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html | [email protected] | ExploitPatchThird Party Advisory |
| https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f | [email protected] | Patch |
| https://web.mit.edu/kerberos/advisories/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mit kerberos 5 | >= 1.18.0, <= 1.22.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | siemens-SADP |
| Jul 8, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | New CVE Received | [email protected] |