Alerts This Week
Warning Icon 1 652
Alerts This Week
Warning Icon 1 652

Ubuntu 26.04 LTS GNU SASL Informational Denial of Service CVE-2026-48829

ubuntu
Calendar Grey June 1, 2026
Dist Ubuntu Esm H88
Update for GNU SASL addresses a denial of service risk from specially crafted input in Ubuntu releases. Critical patch.
GNU SASL could be made to crash if it received specially crafted input.

Summary

GNU SASL could be made to crash if it received specially crafted input.

Software Description:

- gsasl: Simple Authentication and Security Layer framework

Details:

It was discovered that GNU SASL did not properly handle certain DIGEST-MD5

tokens. An attacker could possibly use this issue to cause GNU SASL to

crash, resulting in a denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
  gsasl                           2.2.2-4ubuntu1.1
  libgsasl18                      2.2.2-4ubuntu1.1

Ubuntu 25.10
  gsasl                           2.2.2-2ubuntu1.1
  libgsasl18                      2.2.2-2ubuntu1.1

Ubuntu 24.04 LTS
  gsasl                           2.2.1-1willsync1ubuntu0.1
  libgsasl18                      2.2.1-1willsync1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8356-1

CVE-2026-48829

Severity
informational
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8356-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here