Back to overview

CVE-2026-56968

LOW
3.7
CVSS 3.1
Description
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

Metadata

CVE ID
CVE-2026-56968
State
PUBLISHED
Assigner
mitre
Reserved
2026-06-23 16:18 UTC
Published
2026-06-23 16:18 UTC
Last updated
2026-06-23 17:31 UTC
Primary CWE
CWE-839
CWE-839 Numeric Range Comparison Without Minimum Check
Vendor / Product
GNU / GNU SASL
Sources
cve.org  ·  NVD

Severity & Metrics

3.7 LOW CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
GNU GNU SASL 0 < 2.2.4
Weakness (CWE)
CWESourceDescription
CWE-839 cna CWE-839 Numeric Range Comparison Without Minimum Check
CVSS scores (1)
ScoreSeverityVersionSourceVector
3.7 LOW 3.1 cna CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Back to overview