This update for krb5 fixes the following issues
- CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366).
- CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1033=1
- openSUSE Leap 16.0:
krb5-1.21.3-160000.3.1
krb5-client-1.21.3-160000.3.1
krb5-devel-1.21.3-160000.3.1
krb5-plugin-kdb-ldap-1.21.3-160000.3.1
krb5-plugin-preauth-otp-1.21.3-160000.3.1
krb5-plugin-preauth-pkinit-1.21.3-160000.3.1
krb5-plugin-preauth-spake-1.21.3-160000.3.1
krb5-server-1.21.3-160000.3.1
* bsc#1263366
* bsc#1263367
References:
* https://www.suse.com/security/cve/CVE-2026-40355.html
* https://www.suse.com/security/cve/CVE-2026-40356.html
Get the latest Linux and open source security news straight to your inbox.