Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 43 krb5 Critical NegoEx DoS Issues Fixed 2026-684396998a

fedora
Calendar Grey May 6, 2026
Dist Fedora Esm H88
Fix critical NegoEx parsing issues in Fedora 43's krb5 with essential updates for better security.
Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356) Add upstream patches to build against openssl 4.0 Make configure.ac work with autoconf 2.73

Summary

Kerberos V5 is a trusted-third-party network authentication system,

which can improve your network's security by eliminating the insecure

practice of sending passwords over the network in unencrypted form.

Update Information:

Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356) Add upstream patches to build against openssl 4.0 Make configure.ac work with autoconf 2.73

Change Log

* Tue Apr 28 2026 Julien Rische - 1.22.2-4 - Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356) - resolves: rhbz#2463398 - resolves: rhbz#2463395 - Add upstream patches to build against openssl 4.0 - Make configure.ac work with autoconf 2.73

References


[ 1 ] Bug #2463395 - CVE-2026-40356 krb5: MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2463395 [ 2 ] Bug #2463398 - CVE-2026-40355 krb5: MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2463398

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-684396998a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: krb5
Product: Fedora 43
Version: 1.22.2
Release: 4.fc43
Summary: The Kerberos network authentication system

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here