RHSA-2026:19145HighCVSS 5.9

Red Hat Security Advisory: krb5 security update

Published
May 19, 2026
Last Modified
August 31, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-40355 — krb5: MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism CVE-2026-40356 — krb5: MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read

🎯 Affected products107

  • Red Hat Enterprise Linux AppStream (v. 10)
  • Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-0:1.21.3-10.el10_2.src as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-debuginfo-0:1.21.3-10.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • krb5-debuginfo-0:1.21.3-10.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-debuginfo-0:1.21.3-10.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • krb5-debuginfo-0:1.21.3-10.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-debuginfo-0:1.21.3-10.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • krb5-debuginfo-0:1.21.3-10.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-debuginfo-0:1.21.3-10.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • krb5-debuginfo-0:1.21.3-10.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-debugsource-0:1.21.3-10.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • krb5-debugsource-0:1.21.3-10.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-debugsource-0:1.21.3-10.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • krb5-debugsource-0:1.21.3-10.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-debugsource-0:1.21.3-10.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • krb5-debugsource-0:1.21.3-10.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-debugsource-0:1.21.3-10.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • krb5-debugsource-0:1.21.3-10.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-devel-0:1.21.3-10.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • krb5-devel-0:1.21.3-10.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • krb5-devel-0:1.21.3-10.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • krb5-devel-0:1.21.3-10.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • krb5-libs-0:1.21.3-10.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-libs-0:1.21.3-10.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-libs-0:1.21.3-10.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-libs-0:1.21.3-10.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-libs-debuginfo-0:1.21.3-10.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • krb5-libs-debuginfo-0:1.21.3-10.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • krb5-libs-debuginfo-0:1.21.3-10.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • +77 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, remove the NegoEx mechanism registration from the system's GSSAPI configuration if it is not required. This can typically be achieved by removing or commenting out the relevant entry in `/etc/gss/mech`. A restart of services utilizing Kerberos might be necessary for the changes to take effect, which could impact Kerberos-dependent functionality. Workaround: To mitigate this issue, ensure that the NegoEx mechanism is not registered in the `/etc/gss/mech` configuration file. Removing the corresponding entry from this file will prevent the vulnerable code path from being activated. This action may impact services that rely on the NegoEx GSS-API mechanism. A restart of affected Kerberos-dependent services may be required for the change to take effect.

🔗 References (5)