==========================================================================
Ubuntu Security Notice USN-8585-1
July 22, 2026

krb5 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in Kerberos.

Software Description:
- krb5: MIT Kerberos Network Authentication Protocol

Details:

It was discovered that Kerberos had an integer underflow vulnerability
in the berval2tl_data() function. An attacker could possibly use this issue
to cause Kerberos to crash, resulting in a denial of service.
(CVE-2026-11850)

It was discovered that Kerberos had vulnerabilities in its NegoEx mechanism
parsing. A remote attacker could possibly use these issues to cause
Kerberos to crash, resulting in a denial of service. (CVE-2026-40355,
CVE-2026-40356)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
  krb5-admin-server               1.22.1-2ubuntu4.1
  krb5-kdc                        1.22.1-2ubuntu4.1
  libkrb5-3                       1.22.1-2ubuntu4.1

Ubuntu 24.04 LTS
  krb5-admin-server               1.20.1-6ubuntu2.7
  krb5-kdc                        1.20.1-6ubuntu2.7
  libkrb5-3                       1.20.1-6ubuntu2.7

Ubuntu 22.04 LTS
  krb5-admin-server               1.19.2-2ubuntu0.8
  krb5-kdc                        1.19.2-2ubuntu0.8
  libkrb5-3                       1.19.2-2ubuntu0.8

After a standard system update you need to restart Kerberos to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-8585-1
  CVE-2026-11850, CVE-2026-40355, CVE-2026-40356

Package Information:
  https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1
  https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7
  https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to