Low severity3.7NVD Advisory· Published Jun 23, 2026· Updated Jul 31, 2026
CVE-2026-56968
CVE-2026-56968
Description
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
5- lists.gnu.org/archive/html/help-gsasl/2026-06/msg00000.htmlnvdExploitMailing ListVendor Advisory
- ftp.gnu.org/gnu/gsasl/nvdProduct
- lists.debian.org/debian-security-announce/2026/msg00259.htmlnvdMailing List
- www.gnu.org/software/gsasl/nvdProduct
- lists.debian.org/debian-lts-announce/2026/07/msg00049.htmlnvd
News mentions
0No linked articles in our index yet.