Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

UBUNTU Core 8.1 ssn15 Significant Security Update UBUNTU-SEC-2026-31789-4

suse
Calendar Grey May 15, 2026
Dist Suse Esm H88
Security update for krb5 addresses two issues including denial of service with patches for SUSE Linux Micro.
An update that solves two vulnerabilities can now be installed.

Summary

## This update for krb5 fixes the following issues * CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). * CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-701=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * krb5-mini-1.20.1-8.1 * krb5-mini-debugsource-1.20.1-8.1 * krb5-mini-debuginfo-1.20.1-8.1

References

* bsc#1263366

* bsc#1263367

Cross-

* CVE-2026-40355

* CVE-2026-40356

CVSS scores:

* CVE-2026-40355 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-40355 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-40356 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-40356 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* SUSE Linux Micro 6.0

* SUSE Linux Micro Extras 6.0

An update that solves two vulnerabilities can now be installed.

##

* https://www.suse.com/security/cve/CVE-2026-40355.html

* https://www.suse.com/security/cve/CVE-2026-40356.html

* https://bugzilla.suse.com/show_bug.cgi?id=1263366

* https://bugzilla.suse.com/show_bug.cgi?id=1263367

Announcement ID: SUSE-SU-2026:21641-1
Release Date: 2026-05-09T16:16:13Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here