Out-of-bounds read in Gss-ntlmssp - #VU151096
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the NTLMv1 client-challenge extraction in gssntlm_srv_auth() when processing a Type-3 AUTHENTICATE message with an LM response shorter than eight bytes. A remote attacker can send a specially crafted authentication message to cause a denial of service.
The vulnerable path requires NTLMv1 with extended session security negotiated and an NT response of exactly 24 bytes.