A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-11850

CVE-2026-11850: MIT Kerberos Use-After-Free Vulnerability

CVE-2026-11850 is a use-after-free vulnerability in MIT Kerberos krb5 affecting the LDAP plugin. An integer underflow leads to heap out-of-bounds reads. This article covers technical details, affected systems, and mitigation.

Published: June 11, 2026

CVE-2026-11850 Overview

CVE-2026-11850 is an integer underflow vulnerability [CWE-191] in MIT Kerberos 5 (krb5) affecting the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction bv_len - 2 without validating that bv_len is at least 2. When bv_len is 0 or 1, the value wraps to a large number, which is then truncated to a uint16_t, producing 65534 or 65535. A subsequent memcpy reads up to 65534 bytes from a 1-byte source buffer, causing a heap out-of-bounds read in the KDC or kadmind processes.

Critical Impact

A malicious or compromised Lightweight Directory Access Protocol (LDAP) Kerberos Database (KDB) backend can return a crafted krbExtraData attribute to trigger heap memory disclosure and process crashes in krb5kdc or kadmind.

Affected Products

  • MIT Kerberos 5 (krb5) with LDAP KDB backend enabled
  • Distributions packaging krb5 with the libkdb_ldap plugin (per Red Hat advisory)
  • KDC and kadmind services reading principal data from LDAP

Discovery Timeline

  • 2026-06-11 - CVE CVE-2026-11850 published to NVD
  • 2026-06-11 - Last updated in NVD database

Technical Details for CVE-2026-11850

Vulnerability Analysis

The defect resides in berval2tl_data() within the LDAP KDB plugin. The function converts a BerVal-encoded LDAP attribute into a krb5_tl_data structure. It computes the length of the tagged data payload by subtracting 2 from bv_len, the BerVal length field, without first verifying that bv_len >= 2. Because bv_len is unsigned, values of 0 or 1 wrap around modulo 2^n. The result is then assigned to a uint16_t, producing 0xFFFE (65534) or 0xFFFF (65535).

The code then calls malloc for that small underflowed length and uses memcpy to copy up to 65534 bytes from a buffer that contains only 0 or 1 byte. The read advances past the bounds of the source heap allocation, exposing adjacent heap memory and potentially crashing the process. Confidentiality impact is rated low and availability impact high, reflecting limited leakage but reliable service disruption.

Root Cause

The root cause is a missing lower-bound check on an externally supplied length field before unsigned arithmetic. The fix requires validating bv_len >= 2 prior to the subtraction. This is a classic [CWE-191] integer underflow that escalates into an out-of-bounds read because the result governs a memcpy length.

Attack Vector

Exploitation requires that the KDC or kadmind be configured to read principal data from an LDAP backend the attacker can influence. An adversary with high privileges on the directory, or one who has compromised the LDAP server, returns a krbExtraData attribute with bv_len < 2. When the Kerberos daemon parses the principal, berval2tl_data() underflows and triggers the heap out-of-bounds read. Attack complexity is high because the attacker must control the LDAP response delivered to the KDC.

No verified public proof-of-concept code is available. See the Red Hat CVE-2026-11850 Advisory and the Red Hat Bug #2459970 Report for vendor analysis.

Detection Methods for CVE-2026-11850

Indicators of Compromise

  • Unexpected crashes or SIGSEGV signals in krb5kdc or kadmind processes with stack traces referencing berval2tl_data or ldap_principal2.
  • LDAP audit log entries showing krbExtraData attribute writes containing zero-length or single-byte BerVal values.
  • Heap corruption indicators reported by AddressSanitizer or libc heap checks in Kerberos daemon logs.

Detection Strategies

  • Inspect LDAP directory entries for krbprincipal objects with krbExtraData values shorter than 2 bytes.
  • Enable verbose Kerberos KDC logging and alert on parse errors or abnormal terminations during principal lookups.
  • Correlate LDAP write operations from non-administrative accounts with subsequent KDC service restarts.

Monitoring Recommendations

  • Monitor systemd or init logs for repeated restarts of krb5kdc.service and kadmin.service.
  • Track LDAP bind sources that modify Kerberos principal entries and alert on unexpected origins.
  • Collect core dumps from Kerberos daemons and review for heap read faults in the LDAP KDB plugin.

How to Mitigate CVE-2026-11850

Immediate Actions Required

  • Apply vendor patches for MIT krb5 as soon as packages are published by your distribution.
  • Restrict write access to Kerberos principal entries in LDAP to a minimal set of administrative accounts.
  • Enforce mutual TLS between the KDC and the LDAP backend to prevent injection of malicious BerVal data by a man-in-the-middle.

Patch Information

Refer to the Red Hat CVE-2026-11850 Advisory for affected packages and fixed versions. The upstream MIT krb5 fix adds a bounds check requiring bv_len >= 2 in berval2tl_data() before the subtraction. Rebuild or reinstall the libkdb_ldap plugin from a patched source tree where vendor builds are not yet available.

Workarounds

  • Switch the KDC database backend from LDAP to the local DB2 backend where operationally feasible until patches are applied.
  • Harden LDAP access control lists so that only the KDC service account and trusted administrators can write krbExtraData.
  • Deploy intrusion detection on the LDAP server to flag writes producing zero or one-byte values on Kerberos attributes.
bash
# Example LDAP ACL hardening (OpenLDAP slapd.conf style)
access to attrs=krbExtraData,krbPrincipalKey
    by dn.exact="cn=kdc-service,ou=services,dc=example,dc=com" read
    by dn.exact="cn=krbadmin,ou=admins,dc=example,dc=com" write
    by * none

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeUse After Free

  • Vendor/TechMit Krb5

  • SeverityMEDIUM

  • CVSS Score5.0

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H
  • Impact Assessment
  • ConfidentialityHigh
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-191
  • Technical References
  • Red Hat CVE-2026-11850 Advisory

  • Red Hat Bug #2459970 Report
  • Latest CVEs
  • CVE-2026-50263: X.org X Server Use-After-Free Flaw

  • CVE-2026-21033: Samsung Assistant RCE Vulnerability

  • CVE-2026-21032: Samsung Assistant RCE Vulnerability

  • CVE-2026-50260: X.org X Server Use-After-Free Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English