Impact
A flaw in the gss-ntlmssp library causes a memory leak in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. For each duplicate, the parser allocates new memory for the string value but fails to release the previous allocation. Over time, repeated authentication attempts can exhaust available memory on the client, bringing the system to a halt. The vulnerability is a classic example of CWE‑401 and can be triggered by a malicious or man‑in‑the‑middle server.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 8, where the gss-ntlmssp package implements the NTLM authentication protocol. Systems that rely on this package for authentication are exposed if the same NTLM challenge pattern is replayed, but no other vendors or products are mentioned.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity for this Denial‑of‑Service flaw. The EPSS score of < 1 % signals a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve a network‑based attacker or a man‑in‑the‑middle server that can send crafted NTLM challenge messages. The attacker can repeatedly send duplicated AV_PAIR entries to the client during the NTLM authentication handshake, gradually exhaust client memory, and eventually cause a denial of service.
OpenCVE Enrichment