https://seclists.org/oss-sec/2026/q2/235: CVE-2026-40355, CVE-2026-40356: MIT krb5 1.18+ Unauthenticated Network ad overrun and null pointer defence
Published Apr 27, 2026
·Updated
Affected Software
1 affected component
MIT krb5>=1.18
Frequently Asked Questions
1
What is the severity of CVE-2026-40355 and CVE-2026-40356?
CVE-2026-40355 and CVE-2026-40356 are considered high-severity vulnerabilities due to their potential to allow unauthenticated network attacks.
2
How do I fix CVE-2026-40355 and CVE-2026-40356?
To fix CVE-2026-40355 and CVE-2026-40356, upgrade to the latest version of MIT krb5 that addresses these vulnerabilities.
3
Which versions of MIT krb5 are affected by CVE-2026-40355 and CVE-2026-40356?
MIT krb5 versions 1.18 and later are affected by CVE-2026-40355 and CVE-2026-40356.
4
What are the potential impacts of CVE-2026-40355 and CVE-2026-40356?
The impacts of CVE-2026-40355 and CVE-2026-40356 include denial of service and potential exploitation of the system through network vulnerabilities.
5
What is the context of the vulnerabilities CVE-2026-40355 and CVE-2026-40356?
CVE-2026-40355 and CVE-2026-40356 relate to unauthenticated network NegoEx parsing vulnerabilities in MIT krb5 when calling gss_accept_sec_context() with registered NegoEx mechanisms.