CVE-2026-40356Disclosure(mit / kerberos_5)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-191

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kerberos_5

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-28); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
kerberos_5

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-04-28: 3Mentions · 2026-04-29: 2Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 204-2804-29
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-283
Disclosure1General2
2026-04-292
Disclosure2
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-40355, CVE-2026-40356: MIT krb5 1.18+ Unauthenticated Network read overrun and null pointer dereference https://www.openwall.com/lists/oss-security/2026/04/27/8

    Post summary

    The text announces two new MIT krb5 vulnerabilities (CVE‑2026‑40355 and CVE‑2026‑40356) affecting versions 1.18+, detailing read overrun and null pointer dereference issues, with reference to a security mailing list.

    00031398
    4.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40356 In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a syste… https://www.cve.org/CVERecord?id=CVE-2026-40356 ----- Traducción: CVE-2026-40356 En … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-40356, an integer underflow in MIT Kerberos 5 prior to 1.22.3 that can lead to an out-of-bounds read when gss_accept_sec_context() is called.

    0000057
    73 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40356 In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a syste… https://www.cve.org/CVERecord?id=CVE-2026-40356

    Post summary

    The text discloses that before version 1.22.3 of MIT Kerberos 5, an integer underflow in gss_accept_sec_context() results in an out-of-bounds read.

    00000195
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40356 CVE-2026-40355, CVE-2026-40356 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40356

    Post summary

    The content merely lists CVE-2026-40356 (and CVE-2026-40355) and offers a link to a vulnerability details page, without additional information about the vulnerability or its exploitation.

    0000036
    4.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40355 CVE-2026-40355, CVE-2026-40356 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40355

    Post summary

    The text lists CVE identifiers and a link to a vulnerability details page, without providing additional detail or context.

    0000036
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmitkerberos_5---

Explore more