Security News

Cybersecurity news aggregator

🐧
MEDIUM Updates Debian Security

DSA-6293-1 krb5 - security update

  • What: Security update for krb5
  • Impact: Debian users need to update to fix Kerberos parsing vulnerabilities
Read Full Article →

[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6293-1] krb5 security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6293-1] krb5 security update From: Salvatore Bonaccorso <carnil@debian.org> Date: Fri, 22 May 2026 21:32:08 +0000 Message-id: <[🔎] E1wQXTU-000000083zl-3n6P@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6293-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 22, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : krb5 CVE ID : CVE-2026-40355 Debian Bug : 1135317 Cem Onat Karagun discovered two vulnerabilities in the NegoEx parsing in krb5, the MIT implementation of Kerberos. An unauthenticated remote attacker can take advantage of these flaws to cause a denial of service. For the oldstable distribution (bookworm), this problem has been fixed in version 1.20.1-2+deb12u5. For the stable distribution (trixie), this problem has been fixed in version 1.21.3-5+deb13u1. We recommend that you upgrade your krb5 packages. For the detailed security status of krb5 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/krb5 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmoQyxdfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0R1Dg//cv3YDe9R/fb6MJB1sRYDv1zuNG93PZIatGHVLsW+a4MvJzuc3K+cj3d6 0m0KRSmFJOhM0ITjNyY9dfbpbu4rA6ehKkhJIPABvEY64Jdvi0EFD8HSAw6FwUQ7 SfSfwab+K+2a6oRP3v0D7JvlevKOyEjI2EseXZCAt3P8c7nkgvA+Yed/GGQZdVSS CYvIk+gtyRGuXW6YDUtWG/W+hcU/+5D4cgSHJcRSjBaFrej2nojZPkib/vv8/Hyx qDjf4tgbIwekBAFHnm/H1yvoSmh15aNaRmL7YQwYSS/tuaZJZtBYwiqTJfcWr2xt whTg/1Ut2kweMT/vfU7HT95oS2zxZAsGguPa2Widz2cC5gF06PeMv+Qfcl8xjOlk cN75c9ulR5Py7Pil672lSgBxL5yf7sbabnWyT/EFeJeWRtMzVgq7eNrStbNcdagn +TeipttfwoEZnb3habMEJefiYqK4FLQk7xOFs3oghl7/zVqlw1/6QgJ7LpH7vZV3 w45ftjP98BegvfSejC8XR9bE+1/YQbUpw1tHjjsh7Nu2VEEXfOCQ6iZCleq/O5vE TOuKujqeWi4smOVvuuHZA3upVDPHbaBPZq0DUhyLreo523Xe9eZhXJzhSVjZy663 TJcOJ1SkwdYl+HLIGzUPZ+VO32obLbN0hajXVgrdlJTx/atqND0= =nM2f -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Salvatore Bonaccorso (on-list) Salvatore Bonaccorso (off-list) Prev by Date: [SECURITY] [DSA 6292-1] haveged security update Next by Date: [SECURITY] [DSA 6294-1] libgcrypt20 security update Previous by thread: [SECURITY] [DSA 6292-1] haveged security update Next by thread: [SECURITY] [DSA 6294-1] libgcrypt20 security update Index(es): Date Thread

Share this article