PT-2022-16052 · Helm+2 · Helm+2

·

CVE-2022-23526

·

Published

2022-12-14

·

Updated

2025-11-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Helm versions prior to 3.10.3
Description The issue concerns a NULL Pointer Dereference in the chartutil package that can cause a segmentation violation. This package contains a parser that loads a JSON Schema validation file, which can be used by the Helm client to validate chart values. Certain schema files can cause array data structures to be created, leading to a memory violation. This can result in a Denial of Service when the input causes a panic that cannot be recovered from. The Helm client will panic with a schema file that causes a memory violation panic, but since Helm is not a long-running service, the panic will not affect future uses of the Helm client.
Recommendations For versions prior to 3.10.3, update to version 3.10.3 to resolve the issue. As a temporary workaround, SDK users can validate schema files that are correctly formatted before passing them to the chartutil functions.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1697
ALT-PU-2024-16525
AZL-11656
BIT-HELM-2022-23526
CVE-2022-23526
GHSA-67FX-WX78-JX33
GO-2022-1166
OPENSUSE-SU-2022_4606-1
OPENSUSE-SU-2024:12572-1
OPENSUSE-SU-2025:15779-1
SUSE-SU-2022:4606-1

Affected Products

Alt Linux
Helm
Suse