Description
A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not free the previous allocation when the same AV_PAIR type appears more than once, leaking the earlier allocation. A malicious or man-in-the-middle server can exploit this to cause gradual memory exhaustion on the client during NTLM authentication, leading to a denial of service.
Published: 2026-09-15
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via memory exhaustion during NTLM authentication
Action: Patch
AI Analysis

Impact

A flaw in the gss-ntlmssp library causes a memory leak in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. For each duplicate, the parser allocates new memory for the string value but fails to release the previous allocation. Over time, repeated authentication attempts can exhaust available memory on the client, bringing the system to a halt. The vulnerability is a classic example of CWE‑401 and can be triggered by a malicious or man‑in‑the‑middle server.

Affected Systems

The vulnerability affects Red Hat Enterprise Linux 8, where the gss-ntlmssp package implements the NTLM authentication protocol. Systems that rely on this package for authentication are exposed if the same NTLM challenge pattern is replayed, but no other vendors or products are mentioned.

Risk and Exploitability

The CVSS score of 3.7 indicates low severity for this Denial‑of‑Service flaw. The EPSS score of < 1 % signals a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve a network‑based attacker or a man‑in‑the‑middle server that can send crafted NTLM challenge messages. The attacker can repeatedly send duplicated AV_PAIR entries to the client during the NTLM authentication handshake, gradually exhaust client memory, and eventually cause a denial of service.

Generated by OpenCVE AI on September 17, 2026 at 17:48 UTC.

Remediation

Vendor Workaround

No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.


OpenCVE Recommended Actions

  • No Red Hat‑standard mitigation is available; disabling NTLM may reduce risk.
  • Apply any vendor‑published patch for gss-ntlmssp when it becomes available.
  • Reconfigure authentication services to disable or de‑prioritize NTLM and prefer stronger methods such as Kerberos.
  • Monitor authentication logs and system memory usage for signs of repeated NTLM challenge failures or unexpected memory growth.

Generated by OpenCVE AI on September 17, 2026 at 17:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not free the previous allocation when the same AV_PAIR type appears more than once, leaking the earlier allocation. A malicious or man-in-the-middle server can exploit this to cause gradual memory exhaustion on the client during NTLM authentication, leading to a denial of service.
Title Gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicated av_pair entries in ntlm challenge
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-401
CPEs cpe:/o:redhat:enterprise_linux:8
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-17T14:24:37.383Z

Reserved: 2026-09-15T10:53:12.456Z

Link: CVE-2026-91926

cve-icon Vulnrichment

Updated: 2026-09-17T14:24:27.860Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T12:17:54.500

Modified: 2026-09-17T15:16:57.033

Link: CVE-2026-91926

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-15T00:00:00Z

Links: CVE-2026-91926 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:15:13Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime