Source: gss-ntlmssp Version: 1.3.1-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for gss-ntlmssp. CVE-2026-91926[0]: | A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM | target-info parser when a crafted NTLM CHALLENGE message contains | duplicated string-valued AV_PAIR entries. The parser allocates | memory for each string value but does not free the previous | allocation when the same AV_PAIR type appears more than once, | leaking the earlier allocation. A malicious or man-in-the-middle | server can exploit this to cause gradual memory exhaustion on the | client during NTLM authentication, leading to a denial of service. Only reference is unfortunately the Red Hat bugzilla entry, saying as well that no upstream fix is available. Could you reach out to upstream? If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-91926 https://www.cve.org/CVERecord?id=CVE-2026-91926 [1] https://bugzilla.redhat.com/show_bug.cgi?id=2533698 Regards, Salvatore

