PT-2021-8087 · Heimdal+7 · Heimdal+7

CVE-2022-44640

·

Published

2021-12-09

·

Updated

2025-07-29

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Heimdal versions prior to 7.7.1
Description The issue is related to an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC), which can be exploited by remote attackers to execute arbitrary code. This can also lead to unauthorized access to confidential data, disruption of data integrity, and denial of service.
Recommendations For Heimdal versions prior to 7.7.1, update to version 7.7.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Key Distribution Center (KDC) to minimize the risk of exploitation.

Exploit

Fix

RCE

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3352
ALT-PU-2023-1371
AZL-44388
BDU:2024-06952
CVE-2022-44640
DLA-3206-1
DSA-5287-1
ECHO-BB12-88EF-D3A9
GHSA-88PM-HFMQ-7VV4
MGASA-2022-0468
OESA-2022-2153
OPENSUSE-SU-2023:0019-1
OPENSUSE-SU-2023:0020-1
OPENSUSE-SU-2024:12580-1
OPENSUSE-SU-2024:12587-1
ROSA-SA-2024-2419
USN-5800-1

Affected Products

Alt Linux
Astra Linux
Debian
Freebsd
Heimdal
Linuxmint
Samba
Ubuntu