========================================================================== Ubuntu Security Notice USN-8585-1 July 22, 2026
krb5 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Kerberos. Software Description: - krb5: MIT Kerberos Network Authentication Protocol Details: It was discovered that Kerberos had an integer underflow vulnerability in the berval2tl_data() function. An attacker could possibly use this issue to cause Kerberos to crash, resulting in a denial of service. (CVE-2026-11850) It was discovered that Kerberos had vulnerabilities in its NegoEx mechanism parsing. A remote attacker could possibly use these issues to cause Kerberos to crash, resulting in a denial of service. (CVE-2026-40355, CVE-2026-40356) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS krb5-admin-server 1.22.1-2ubuntu4.1 krb5-kdc 1.22.1-2ubuntu4.1 libkrb5-3 1.22.1-2ubuntu4.1 Ubuntu 24.04 LTS krb5-admin-server 1.20.1-6ubuntu2.7 krb5-kdc 1.20.1-6ubuntu2.7 libkrb5-3 1.20.1-6ubuntu2.7 Ubuntu 22.04 LTS krb5-admin-server 1.19.2-2ubuntu0.8 krb5-kdc 1.19.2-2ubuntu0.8 libkrb5-3 1.19.2-2ubuntu0.8 After a standard system update you need to restart Kerberos to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8585-1 CVE-2026-11850, CVE-2026-40355, CVE-2026-40356 Package Information: https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1 https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7 https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8
signature.asc
Description: OpenPGP digital signature
