PT-2021-8087 · Heimdal+7 · Heimdal+7
CVE-2022-44640
·
Published
2021-12-09
·
Updated
2025-07-29
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Heimdal versions prior to 7.7.1
Description
The issue is related to an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC), which can be exploited by remote attackers to execute arbitrary code. This can also lead to unauthorized access to confidential data, disruption of data integrity, and denial of service.
Recommendations
For Heimdal versions prior to 7.7.1, update to version 7.7.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Key Distribution Center (KDC) to minimize the risk of exploitation.
Exploit
Fix
RCE
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Freebsd
Heimdal
Linuxmint
Samba
Ubuntu