PT-2022-5138 · Libksba+10 · Libksba+10

Tej Rathi

·

Published

2022-10-17

·

Updated

2025-10-17

·

CVE-2022-3515

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Libksba (affected versions not specified)
Description A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment. This issue is related to the parsing of ASN.1 structures used in S/MIME, X.509, and CMS, which can lead to the execution of arbitrary code when handling encrypted or signed data in GnuPG.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2022:7089
ALSA-2022:7090
ALT-PU-2022-7646
ALT-PU-2023-4953
ALT-PU-2025-7370
AZL-13005
BDU:2022-06395
CESA-2022_7088
CESA-2022_7089
CVE-2022-3515
DLA-3153-1
DSA-5255-1
JLSEC-2025-93
MGASA-2022-0404
OESA-2022-2021
OPENSUSE-SU-2022_3683-1
OPENSUSE-SU-2024:12418-1
RHSA-2022:7088
RHSA-2022:7089
RHSA-2022:7090
RHSA-2022:7209
RHSA-2022:7283
RHSA-2022:7927
RHSA-2022:8598
RHSA-2022_7088
RHSA-2022_7089
RHSA-2022_7090
RLSA-2022:7089
RLSA-2022:7090
ROSA-SA-2023-2170
SUSE-SU-2022:3681-1
SUSE-SU-2022:3683-1
SUSE-SU-2022_3681-1
SUSE-SU-2022_3683-1
USN-5688-1
USN-5688-2
ZDI-22-1463
ZDI-22-1464
ZDI-22-1465

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Libksba
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu