From 7841581cb46fea5c6c6c246f4f512ce3c86ce844 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Tue, 28 Apr 2026 18:59:49 +0200 Subject: [PATCH] krb5 1.21.1-10 - Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356) Resolves: RHEL-171591 RHEL-171593 Signed-off-by: Julien Rische --- ...x-two-NegoEx-parsing-vulnerabilities.patch | 65 +++++++++++++++++++ krb5.spec | 7 +- 2 files changed, 71 insertions(+), 1 deletion(-) create mode 100644 0044-Fix-two-NegoEx-parsing-vulnerabilities.patch diff --git a/0044-Fix-two-NegoEx-parsing-vulnerabilities.patch b/0044-Fix-two-NegoEx-parsing-vulnerabilities.patch new file mode 100644 index 0000000..29780f0 --- /dev/null +++ b/0044-Fix-two-NegoEx-parsing-vulnerabilities.patch @@ -0,0 +1,65 @@ +From b0a559e0e46687bf23f8c61fc27e7cda182eb1c4 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 8 Apr 2026 17:57:59 -0400 +Subject: [PATCH] Fix two NegoEx parsing vulnerabilities + +In parse_nego_message(), check the result of the second call to +vector_base() before dereferencing it. In parse_message(), check for +a short header_len to prevent an integer underflow when calculating +the remaining message length. + +Reported by Cem Onat Karagun. + +CVE-2026-40355: + +In MIT krb5 release 1.18 and later, if an application calls +gss_accept_sec_context() on a system with a NegoEx mechanism +registered in /etc/gss/mech, an unauthenticated remote attacker can +trigger a null pointer dereference, causing the process to terminate. + +CVE-2026-40356: + +In MIT krb5 release 1.18 and later, if an application calls +gss_accept_sec_context() on a system with a NegoEx mechanism +registered in /etc/gss/mech, an unauthenticated remote attacker can +trigger a read overrun of up to 52 bytes, possibly causing the process +to terminate. Exfiltration of the bytes read does not appear +possible. + +ticket: 9205 (new) +tags: pullup +target_version: 1.22-next + +(cherry picked from commit 2e75f0d9362fb979f5fc92829431a590a130929f) +--- + src/lib/gssapi/spnego/negoex_util.c | 7 ++++++- + 1 file changed, 6 insertions(+), 1 deletion(-) + +diff --git a/src/lib/gssapi/spnego/negoex_util.c b/src/lib/gssapi/spnego/negoex_util.c +index edc5462e84..a65238e573 100644 +--- a/src/lib/gssapi/spnego/negoex_util.c ++++ b/src/lib/gssapi/spnego/negoex_util.c +@@ -253,6 +253,10 @@ parse_nego_message(OM_uint32 *minor, struct k5input *in, + offset = k5_input_get_uint32_le(in); + count = k5_input_get_uint16_le(in); + p = vector_base(offset, count, EXTENSION_LENGTH, msg_base, msg_len); ++ if (p == NULL) { ++ *minor = ERR_NEGOEX_INVALID_MESSAGE_SIZE; ++ return GSS_S_DEFECTIVE_TOKEN; ++ } + for (i = 0; i < count; i++) { + extension_type = load_32_le(p + i * EXTENSION_LENGTH); + if (extension_type & EXTENSION_FLAG_CRITICAL) { +@@ -391,7 +395,8 @@ parse_message(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, struct k5input *in, + msg_len = k5_input_get_uint32_le(in); + conv_id = k5_input_get_bytes(in, GUID_LENGTH); + +- if (in->status || msg_len > token_remaining || header_len > msg_len) { ++ if (in->status || msg_len > token_remaining || ++ header_len < (size_t)(in->ptr - msg_base) || header_len > msg_len) { + *minor = ERR_NEGOEX_INVALID_MESSAGE_SIZE; + return GSS_S_DEFECTIVE_TOKEN; + } +-- +2.53.0 + diff --git a/krb5.spec b/krb5.spec index c2666b9..97c2bed 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 9 +%global baserelease 10 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -103,6 +103,7 @@ Patch0040: 0040-Improve-ulog-block-resize-efficiency.patch Patch0041: 0041-Add-xrealmauthz-KDC-policy-module-and-tests.patch Patch0042: 0042-Fix-uninitialized-pointer-dereference-in-libkrad.patch Patch0043: 0043-downstream-Install-xrealmauthz-like-other-plugins.patch +Patch0044: 0044-Fix-two-NegoEx-parsing-vulnerabilities.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -767,6 +768,10 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Tue Apr 28 2026 Julien Rische - 1.21.1-10 +- Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356) + Resolves: RHEL-171591 RHEL-171593 + * Fri Jan 30 2026 Julien Rische - 1.21.1-9 - krad: packet ID fetched from uninitialized variable Resolves: RHEL-145355