CVE-2026-40356: Mit Kerberos 5

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.

Affected products

  • Mit Kerberos 5: from 1.18.0, up to and including 1.22.2

Published 2026-04-28. Last modified 2026-07-08.