Junglewise Threat Intelligence

CVE-2026-40356: MIT Kerberos 5 integer underflow in NegoEx message parsing

CVE-2026-40356 · Severity: medium · CVSS 5.9 · Published 2026-04-28

Technologies: Mit Kerberos 5. Vendors: Mit.

Executive brief

MIT Kerberos 5 is a widely used authentication protocol integrated into major operating systems and Microsoft Active Directory. A vulnerability in its message parsing component allows an unauthenticated remote attacker to send a specially crafted network packet that causes the authentication service to crash. This results in a denial-of-service, potentially preventing users from logging into enterprise systems and accessing network resources.

Technical details

An integer underflow vulnerability exists in the parse_message() function within src/lib/gssapi/spnego/negoex_util.c of MIT Kerberos 5. The flaw is triggered when a short header_len is provided in a NegoEx message, leading to an incorrect calculation of the remaining message length and a subsequent out-of-bounds read of up to 52 bytes. This can be exploited by an unauthenticated remote attacker if the target system has a NegoEx mechanism registered in /etc/gss/mech and calls gss_accept_sec_context(). While the out-of-bounds read can cause a process crash (denial-of-service), the vendor indicates that exfiltration of the read memory is unlikely. The issue is fixed in version 1.22.3.

Affected products

  • MIT Kerberos 5 1.18.0 to 1.22.2

Timeline

  • 2026-04-27: disclosed: Initial disclosure by researcher Cem Onat Karagun
  • 2026-04-28: advisory: NVD and MITRE published advisory
  • 2026-04-28: patched: Fixed in upstream commit 2e75f0d

References

Related threats