Home / mailings [USN-8585-1] Kerberos vulnerabilities
Posted on 22 July 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8585-1
July 22, 2026
krb5 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in Kerberos.
Software Description:
- krb5: MIT Kerberos Network Authentication Protocol
Details:
It was discovered that Kerberos had an integer underflow vulnerability
in the berval2tl_data() function. An attacker could possibly use this issue
to cause Kerberos to crash, resulting in a denial of service.
(CVE-2026-11850)
It was discovered that Kerberos had vulnerabilities in its NegoEx mechanism
parsing. A remote attacker could possibly use these issues to cause
Kerberos to crash, resulting in a denial of service. (CVE-2026-40355,
CVE-2026-40356)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
krb5-admin-server 1.22.1-2ubuntu4.1
krb5-kdc 1.22.1-2ubuntu4.1
libkrb5-3 1.22.1-2ubuntu4.1
Ubuntu 24.04 LTS
krb5-admin-server 1.20.1-6ubuntu2.7
krb5-kdc 1.20.1-6ubuntu2.7
libkrb5-3 1.20.1-6ubuntu2.7
Ubuntu 22.04 LTS
krb5-admin-server 1.19.2-2ubuntu0.8
krb5-kdc 1.19.2-2ubuntu0.8
libkrb5-3 1.19.2-2ubuntu0.8
After a standard system update you need to restart Kerberos to make
all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8585-1
CVE-2026-11850, CVE-2026-40355, CVE-2026-40356
Package Information:
https://launchpad.net/ubuntu/+source/krb5/1.22.1-2ubuntu4.1
https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.7
https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.8
--===============3170439965722189646==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
