CVE-2026-56968CWE-839CWE-908

CVE-2026-56968

Low · published June 23, 2026

CVSS v3.1
3.7
EPSS
0%
Percentile
20.8
In the wild
Unconfirmed
What it is

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

The record
Technical detail
CVSS v3.1
3.7 · LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00286 · 20.8th percentile
Weaknesses
CWE-839 · Numeric Range Comparison Without Minimum Check; CWE-908 · Use of Uninitialized Resource
Published
2026-06-23T21:17Z
Affected products (2)
ProductVersionsFixed in
gnu/sasl< 2.2.42.2.4
debian/debian_linuxall versions
References (5)
EPSS history
Timeline
  • 23 JUN 16:18Z
    GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a…
    cvelistv5