{"id":"CVE-2026-56968","title":"GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.","summary":"GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-839","CWE-908"],"vendor":"gnu","product":"sasl","affected":["sasl < 2.2.4","debian_linux = 13.0"],"patched":["sasl 2.2.4"],"published":"2026-06-23","updated":"2026-07-31","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56968","references":[{"url":"https://ftp.gnu.org/gnu/gsasl/","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-security-announce/2026/msg00259.html","label":"cve@mitre.org"},{"url":"https://lists.gnu.org/archive/html/help-gsasl/2026-06/msg00000.html","label":"cve@mitre.org"},{"url":"https://www.gnu.org/software/gsasl/","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2026/07/msg00049.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00413,"epssPercentile":0.32843,"ingestedAt":"2026-07-31T22:04:41.253Z","slug":"CVE-2026-56968","body":"## Overview\n\nGNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.\n\n## Affected\n\n- `sasl < 2.2.4`\n- `debian_linux = 13.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `sasl 2.2.4`","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}