CVE-2026-56968 Details
Description
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
A memory disclosure vulnerability has been identified in the GNU SASL library, specifically in versions prior to 2.2.4. The issue arises in the NTLM client implementation, where a short challenge from a server is not properly sanitized. This lack of sanitization can lead to the disclosure of heap memory. When the NTLM client receives a crafted Type-2 challenge message, the uninitialized portion of the challenge is leaked back to the server within the NTLM response, creating a potential avenue for exploitation.
Users are advised to upgrade to GNU SASL version 2.2.4 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2026/07/msg00049.html | CVE | |
| https://ftp.gnu.org/gnu/gsasl/ | [email protected] | Product |
| https://lists.debian.org/debian-security-announce/2026/msg00259.html | [email protected] | Mailing List |
| https://lists.gnu.org/archive/html/help-gsasl/2026-06/msg00000.html | [email protected] | ExploitMailing ListVendor Advisory |
| https://www.gnu.org/software/gsasl/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-908 | Use of Uninitialized Resource | [email protected] |
| CWE-839 | Numeric Range Comparison Without Minimum Check | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gnu sasl | < 2.2.4 |
CPE
Remediation
| |
| debian debian linux | 13.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 31, 2026 | CVE Modified | CVE |
| Jun 29, 2026 | Initial Analysis | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |