krb5 1.21.1-10

- Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)
  Resolves: RHEL-171591 RHEL-171593

Signed-off-by: Julien Rische <jrische@redhat.com>
This commit is contained in:
Julien Rische 2026-04-28 18:59:49 +02:00
parent 57f5430401
commit 7841581cb4
2 changed files with 71 additions and 1 deletions

View File

@ -0,0 +1,65 @@
From b0a559e0e46687bf23f8c61fc27e7cda182eb1c4 Mon Sep 17 00:00:00 2001
From: Greg Hudson <ghudson@mit.edu>
Date: Wed, 8 Apr 2026 17:57:59 -0400
Subject: [PATCH] Fix two NegoEx parsing vulnerabilities
In parse_nego_message(), check the result of the second call to
vector_base() before dereferencing it. In parse_message(), check for
a short header_len to prevent an integer underflow when calculating
the remaining message length.
Reported by Cem Onat Karagun.
CVE-2026-40355:
In MIT krb5 release 1.18 and later, if an application calls
gss_accept_sec_context() on a system with a NegoEx mechanism
registered in /etc/gss/mech, an unauthenticated remote attacker can
trigger a null pointer dereference, causing the process to terminate.
CVE-2026-40356:
In MIT krb5 release 1.18 and later, if an application calls
gss_accept_sec_context() on a system with a NegoEx mechanism
registered in /etc/gss/mech, an unauthenticated remote attacker can
trigger a read overrun of up to 52 bytes, possibly causing the process
to terminate. Exfiltration of the bytes read does not appear
possible.
ticket: 9205 (new)
tags: pullup
target_version: 1.22-next
(cherry picked from commit 2e75f0d9362fb979f5fc92829431a590a130929f)
---
src/lib/gssapi/spnego/negoex_util.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/src/lib/gssapi/spnego/negoex_util.c b/src/lib/gssapi/spnego/negoex_util.c
index edc5462e84..a65238e573 100644
--- a/src/lib/gssapi/spnego/negoex_util.c
+++ b/src/lib/gssapi/spnego/negoex_util.c
@@ -253,6 +253,10 @@ parse_nego_message(OM_uint32 *minor, struct k5input *in,
offset = k5_input_get_uint32_le(in);
count = k5_input_get_uint16_le(in);
p = vector_base(offset, count, EXTENSION_LENGTH, msg_base, msg_len);
+ if (p == NULL) {
+ *minor = ERR_NEGOEX_INVALID_MESSAGE_SIZE;
+ return GSS_S_DEFECTIVE_TOKEN;
+ }
for (i = 0; i < count; i++) {
extension_type = load_32_le(p + i * EXTENSION_LENGTH);
if (extension_type & EXTENSION_FLAG_CRITICAL) {
@@ -391,7 +395,8 @@ parse_message(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, struct k5input *in,
msg_len = k5_input_get_uint32_le(in);
conv_id = k5_input_get_bytes(in, GUID_LENGTH);
- if (in->status || msg_len > token_remaining || header_len > msg_len) {
+ if (in->status || msg_len > token_remaining ||
+ header_len < (size_t)(in->ptr - msg_base) || header_len > msg_len) {
*minor = ERR_NEGOEX_INVALID_MESSAGE_SIZE;
return GSS_S_DEFECTIVE_TOKEN;
}
--
2.53.0

View File

@ -10,7 +10,7 @@
#
# baserelease is what we have standardized across Fedora and what
# rpmdev-bumpspec knows how to handle.
%global baserelease 9
%global baserelease 10
# This should be e.g. beta1 or %%nil
%global pre_release %nil
@ -103,6 +103,7 @@ Patch0040: 0040-Improve-ulog-block-resize-efficiency.patch
Patch0041: 0041-Add-xrealmauthz-KDC-policy-module-and-tests.patch
Patch0042: 0042-Fix-uninitialized-pointer-dereference-in-libkrad.patch
Patch0043: 0043-downstream-Install-xrealmauthz-like-other-plugins.patch
Patch0044: 0044-Fix-two-NegoEx-parsing-vulnerabilities.patch
License: MIT
URL: https://web.mit.edu/kerberos/www/
@ -767,6 +768,10 @@ exit 0
%{_datarootdir}/%{name}-tests/%{_arch}
%changelog
* Tue Apr 28 2026 Julien Rische <jrische@redhat.com> - 1.21.1-10
- Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)
Resolves: RHEL-171591 RHEL-171593
* Fri Jan 30 2026 Julien Rische <jrische@redhat.com> - 1.21.1-9
- krad: packet ID fetched from uninitialized variable
Resolves: RHEL-145355