Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not free the previous allocation when the same AV_PAIR type appears more than once, leaking the earlier allocation. A malicious or man-in-the-middle server can exploit this to cause gradual memory exhaustion on the client during NTLM authentication, leading to a denial of service. | |
| Title | Gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicated av_pair entries in ntlm challenge | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-401 | |
| CPEs | cpe:/o:redhat:enterprise_linux:8 | |
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-15T11:49:10.516Z
Reserved: 2026-09-15T10:53:12.456Z
Link: CVE-2026-91926
No data.
Status : Received
Published: 2026-09-15T12:17:54.500
Modified: 2026-09-15T12:17:54.500
Link: CVE-2026-91926
No data.
OpenCVE Enrichment
No data.
