Memory Leak Vulnerability in gss-ntlmssp Affects Red Hat Products
CVE-2026-91926
3.7LOW
What is CVE-2026-91926?
A flaw in gss-ntlmssp leads to a memory leak in the NTLM target-info parser when processing crafted NTLM CHALLENGE messages with duplicated AV_PAIR entries. Each time such an entry is encountered, the parser allocates memory but fails to release previous allocations, resulting in excessive memory use over time. This vulnerability can be exploited by a malicious actor or a man-in-the-middle server to gradually exhaust the client's memory during NTLM authentication, potentially resulting in a denial of service.
References
CVSS V3.1
Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Chase Bevan-Thomas (cbev0x) (Independent security researcher) for reporting this issue.