CVE-2026-56968
published 2026-06-23CVE-2026-56968: GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.29%
20.7th percentile
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| gnu | gnu_sasl | < 2.2.4 | 2.2.4 |
| gnu | sasl | < 2.2.4 | 2.2.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNU SASL up to 2.2.3 numeric range comparison without minimum check
vuldb·2026-06-24·CVSS 3.7
CVE-2026-56968 [LOW] GNU SASL up to 2.2.3 numeric range comparison without minimum check
A vulnerability labeled as problematic has been found in GNU SASL up to 2.2.3. The affected element is an unknown function. Such manipulation leads to numeric range comparison without minimum check.
This vulnerability is uniquely identified as CVE-2026-56968. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
GHSA
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
ghsa_unreviewed·2026-06-23
CVE-2026-56968 [LOW] CWE-839 GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-23
Published