Memory Leak Vulnerability in gss-ntlmssp Affects Red Hat Products
CVE-2026-91926

3.7LOW

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
15 September 2026

What is CVE-2026-91926?

A flaw in gss-ntlmssp leads to a memory leak in the NTLM target-info parser when processing crafted NTLM CHALLENGE messages with duplicated AV_PAIR entries. Each time such an entry is encountered, the parser allocates memory but fails to release previous allocations, resulting in excessive memory use over time. This vulnerability can be exploited by a malicious actor or a man-in-the-middle server to gradually exhaust the client's memory during NTLM authentication, potentially resulting in a denial of service.

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Chase Bevan-Thomas (cbev0x) (Independent security researcher) for reporting this issue.
.