Source: gss-ntlmssp
Version: 1.3.1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for gss-ntlmssp.

CVE-2026-91926[0]:
| A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM
| target-info parser when a crafted NTLM CHALLENGE message contains
| duplicated string-valued AV_PAIR entries. The parser allocates
| memory for each string value but does not free the previous
| allocation when the same AV_PAIR type appears more than once,
| leaking the earlier allocation. A malicious or man-in-the-middle
| server can exploit this to cause gradual memory exhaustion on the
| client during NTLM authentication, leading to a denial of service.

Only reference is unfortunately the Red Hat bugzilla entry, saying as
well that no upstream fix is available. Could you reach out to
upstream?


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-91926
    https://www.cve.org/CVERecord?id=CVE-2026-91926
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2533698

Regards,
Salvatore

Reply via email to