CVE-2026-56968: Medium severity GNU GNU SASL vulnerability
Published Jun 23, 2026
·Updated
GNU SASL before 2.2.4 lacks sanitization of a short challenge in gsaslntlmclientstep in the NTLM client, which could result in memory disclosure via a crafted server.
Affected Software
3 affected components
GNU GNU SASL<2.2.4
GNU SASL<2.2.4
Debian Debian Linux=13.0
Event History
Jun 23, 2026
CVE Published
via MITRE·04:18 PM
Data Sourced
via MITRE·04:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-56968?
The severity of CVE-2026-56968 is classified as low with a score of 3.7.
2
What is CVE-2026-56968 about?
CVE-2026-56968 involves a lack of sanitization in the NTLM client of GNU SASL before version 2.2.4, potentially leading to memory disclosure.
3
How do I fix CVE-2026-56968?
To fix CVE-2026-56968, you should upgrade to GNU SASL version 2.2.4 or later.
4
What are the potential impacts of CVE-2026-56968?
The potential impact of CVE-2026-56968 is memory disclosure due to a crafted server challenge.
5
Which software is affected by CVE-2026-56968?
CVE-2026-56968 affects GNU SASL versions prior to 2.2.4.