Kerberos Vulnerabilities Lead to Denial of Service Risks

Kerberos Vulnerabilities Lead to Denial of Service Risks

First seen 23 Jul 2026, 01:23 UTC UbuntuLinuxsecuritylaunchpad.net 92% similarity 70.5

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities were discovered in Kerberos, specifically an integer underflow in the berval2tl_data() function (CVE-2026-11850) and issues in the NegoEx mechanism parsing (CVE-2026-40355, CVE-2026-40356). These vulnerabilities could allow remote attackers to crash Kerberos, resulting in denial of service. The vulnerabilities affect various versions of the MIT Kerberos Network Authentication Protocol. Users are advised to update their systems to the latest package versions to mitigate these risks. Affected systems include Ubuntu 26.04 LTS and earlier versions. After applying updates, a restart of Kerberos is necessary to implement changes. The vulnerabilities were disclosed in July 2026, with prior CVE publications dating back to April and June 2026.

Key Points: • Kerberos has critical vulnerabilities that can lead to denial of service attacks. • Affected CVEs include CVE-2026-11850, CVE-2026-40355, and CVE-2026-40356. • Users must update their systems and restart Kerberos to apply necessary security fixes.

ThreatCluster AI

Timeline

2026-04-28
CVE-2026-40355 and CVE-2026-40356 published
Two vulnerabilities in Kerberos were published, allowing potential denial of service attacks.
Linuxsecurity
2026-06-11
CVE-2026-11850 published
An integer underflow vulnerability in Kerberos was disclosed, enabling denial of service.
Ubuntu
2026-07-22
Kerberos vulnerabilities disclosed
Ubuntu released a security notice detailing multiple vulnerabilities in Kerberos affecting various versions.
Ubuntu
2026-07-22
Patch released for Kerberos vulnerabilities
Ubuntu provided updates for affected Kerberos packages and advised users to restart the service post-update.
Linuxsecurity

Community

Browse all →