Executive brief
MIT Kerberos 5 is a widely used authentication protocol integrated into major operating systems and Microsoft Active Directory. A vulnerability in its message parsing component allows an unauthenticated remote attacker to send a specially crafted network packet that causes the authentication service to crash. This results in a denial-of-service, potentially preventing users from logging into enterprise systems and accessing network resources.
Technical details
An integer underflow vulnerability exists in the parse_message() function within src/lib/gssapi/spnego/negoex_util.c of MIT Kerberos 5. The flaw is triggered when a short header_len is provided in a NegoEx message, leading to an incorrect calculation of the remaining message length and a subsequent out-of-bounds read of up to 52 bytes. This can be exploited by an unauthenticated remote attacker if the target system has a NegoEx mechanism registered in /etc/gss/mech and calls gss_accept_sec_context(). While the out-of-bounds read can cause a process crash (denial-of-service), the vendor indicates that exfiltration of the read memory is unlikely. The issue is fixed in version 1.22.3.
Affected products
- MIT Kerberos 5 1.18.0 to 1.22.2
Timeline
- 2026-04-27: disclosed: Initial disclosure by researcher Cem Onat Karagun
- 2026-04-28: advisory: NVD and MITRE published advisory
- 2026-04-28: patched: Fixed in upstream commit 2e75f0d