Executive brief
GNU SASL is a library used by applications to handle secure authentication. A vulnerability in its NTLM client component could allow a malicious server to trick a connecting application into revealing small amounts of its private memory. This could lead to the exposure of sensitive information from the application's memory to the operator of the malicious server.
Technical details
A vulnerability exists in the _gsasl_ntlm_client_step function within the NTLM client of GNU SASL before version 2.2.4. The component fails to properly sanitize or zero-initialize a memory buffer (tSmbNtlmAuthChallenge) when receiving a Type-2 challenge from a server that is shorter than the expected 1076 bytes. Because the buffer is allocated using malloc() rather than calloc(), the trailing uninitialized heap memory is subsequently processed by libntlm and included in the client's NTLM response. A malicious server can exploit this to trigger a remote heap memory disclosure. The issue is addressed in version 2.2.4 by ensuring proper initialization and input validation.
Affected products
- GNU GNU SASL before 2.2.4
Timeline
- 2026-06-15: disclosed: Vulnerability reported to GNU SASL maintainers
- 2026-06-15: patched: GNU SASL 2.2.4 released with fix
- 2026-06-16: advisory: Debian security advisory DSA-6348-1 published
- 2026-06-23: advisory: CVE-2026-56968 published to NVD