CVE-2026-40355General(mit / kerberos_5)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mit kerberos_5 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kerberos_5

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-04-28); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
kerberos_5

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-04-28: 3Mentions · 2026-04-29: 2Mentions · 2026-05-02: 1Mentions · 2026-05-25: 1Mentions · 2026-06-03: 1Patch / Workaround · 2026-05-02: 1Patch / Workaround · 2026-05-25: 1Patch / Workaround · 2026-06-03: 1Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 2Technical Details · 2026-05-02: 1Technical Details · 2026-06-03: 104-2804-2905-0205-2506-03
Signal classification3 categories
General
337.5%
Patch
337.5%
Disclosure
225.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-283
Disclosure1General2
2026-04-292
Disclosure1General1
2026-05-021
Patch1
2026-05-251
Patch1
2026-06-031
Patch1
Full discourse8 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-40355, CVE-2026-40356: MIT krb5 1.18+ Unauthenticated Network read overrun and null pointer dereference https://www.openwall.com/lists/oss-security/2026/04/27/8

    Post summary

    The message announces that MIT krb5 1.18+ suffers from a read‑overrun and null‑pointer dereference (CVE‑2026‑40355/56) but does not provide a PoC, exploit, or patch information.

    00031398
    4.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    CVE-2026-40355 (krb5) is fixed. Next month? Another CVE. Stop chasing one-off patches. Learn to check, mitigate, and automate instead. Read more -> http://tinyurl.com/2srhkx89 #Security https://t.co/GOPnLuN1gj

    Post summary

    The tweet announces that CVE-2026-40355 in krb5 has been fixed and advises prioritizing proactive patch management rather than chasing single patches.

    1000060
    1.5K followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-40355 is a Kerberos DoS, not credential theft—so of course it still wrecks your day. Patch MIT krb5 1.22.3 and audit NegoEx; “just a crash” turns into outage. https://windowsforum.com/threads/cve-2026-40355-mit-kerberos-dos-patch-mit-krb5-1-22-3-and-review-negoex.422088/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #DenialOfService #MitKerberos #GssapiSecurityContexts #NegoexMechanism https://t.co/kaCNDXPXaS

    Post summary

    CVE‑2026‑40355 is a Kerberos denial‑of‑service vulnerability; the post advises applying the MIT krb5 1.22.3 patch and auditing NegoEx, with no evidence of active exploitation or a proof‑of‑concept reported.

    0000034
    1.1K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Fedora sysadmins: Two Kerberos flaws (CVE-2026-40355/40356) can crash your authentication services. I've posted the complete guide – includes a fix script and firewall workarounds. Read more-> https://tinyurl.com/3jz38jwz #Fedora https://t.co/ekUsdNGbPY

    Post summary

    The tweet announces two Kerberos flaws and provides a guide with a fix script and firewall workarounds rather than a PoC or active exploitation report.

    0000062
    1.5K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-40355 In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism r… https://www.cve.org/CVERecord?id=CVE-2026-40355 ----- Traducción: CVE-2026-40355 En … http://infoflow.cloud`

    Post summary

    The note announces CVE‑2026‑40355, detailing a NULL pointer dereference flaw in MIT Kerberos 5 versions prior to 1.22.3 that occurs when calling gss_accept_sec_context() on systems with a NegoEx mechanism, and it links to the official CVE record.

    0000058
    73 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40355 In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism r… https://www.cve.org/CVERecord?id=CVE-2026-40355

    Post summary

    The tweet references CVE-2026-40355, provides a brief technical description of a NULL pointer dereference in MIT Kerberos, and links to the official CVE record, without any additional exploitation or mitigation details.

    00000199
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40356 CVE-2026-40355, CVE-2026-40356 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40356

    Post summary

    The post merely lists CVE identifiers and a link to a vulnerability detail page without providing additional actionable or technical information.

    0000036
    4.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40355 CVE-2026-40355, CVE-2026-40356 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40355

    Post summary

    The post simply lists CVE identifiers and shares a link to a vulnerability details page, without providing any substantive content about the vulnerability or its exploitation.

    0000036
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmitkerberos_5---

Explore more