Back Linuxsecurity Ubuntu 26.04 LTS Kerberos Important DoS Issues USN-8585-1 CVE-2026
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
Several security issues were fixed in Kerberos. Software Description: - krb5: MIT Kerberos Network Authentication Protocol Details: It was discovered that Kerberos had an integer underflow vulnerability in the berval2tl_data() function. An attacker could possibly use this issue to cause Kerberos to crash, resulting in a denial of service. (CVE-2026-11850) It was discovered that Kerberos had vulnerabilities in its NegoEx mechanism parsing. A remote attacker could possibly use these issues to cause Kerberos to crash, resulting in a denial of service. (CVE-2026-40355, CVE-2026-40356)
Several security issues were fixed in Kerberos.
Software Description:
- krb5: MIT Kerberos Network Authentication Protocol
It was discovered that Kerberos had an integer underflow vulnerability
in the berval2tl_data() function. An attacker could possibly use this issue
to cause Kerberos to crash, resulting in a denial of service.
It was discovered that Kerberos had vulnerabilities in its NegoEx mechanism
parsing. A remote attacker could possibly use these issues to cause
Kerberos to crash, resulting in a denial of service. (CVE-2026-40355,
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS krb5-admin-server 1.22.1-2ubuntu4.1 krb5-kdc 1.22.1-2ubuntu4.1 libkrb5-3 1.22.1-2ubuntu4.1 Ubuntu 24.04 LTS krb5-admin-server 1.20.1-6ubuntu2.7 krb5-kdc 1.20.1-6ubuntu2.7 libkrb5-3 1.20.1-6ubuntu2.7 Ubuntu 22.04 LTS krb5-admin-server 1.19.2-2ubuntu0.8 krb5-kdc 1.19.2-2ubuntu0.8 libkrb5-3 1.19.2-2ubuntu0.8 After a standard system update you need to restart Kerberos to make all the necessary changes.
CVE-2026-11850, CVE-2026-40355, CVE-2026-40356
Ubuntu Security Notice USN-8585-1
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
