PT-2022-5570 · Mit+13 · Mit Kerberos 5+12

Greg Hudson

·

Published

2022-11-15

·

Updated

2026-04-13

·

CVE-2022-42898

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MIT Kerberos 5 versions prior to 1.19.4 and 1.20.x prior to 1.20.1 Heimdal versions prior to 7.7.1 Samba versions prior to 4.15.12, 4.16.7, and 4.17.3
Description The issue is related to integer overflows in the PAC parsing in MIT Kerberos 5 and Heimdal, which may lead to remote code execution on 32-bit platforms and cause a denial of service on other platforms. This occurs in the krb5 pac parse function in lib/krb5/krb/pac.c. The vulnerability can be exploited by sending a specially crafted request to a KDC server, allowing an authenticated attacker to overflow a buffer with controlled data. Successful exploitation can lead to denial of service or remote code execution.
Recommendations For MIT Kerberos 5 versions prior to 1.19.4 and 1.20.x prior to 1.20.1, update to version 1.19.4 or 1.20.1 or later. For Heimdal versions prior to 7.7.1, update to version 7.7.1 or later. For Samba versions prior to 4.15.12, 4.16.7, and 4.17.3, update to version 4.15.12, 4.16.7, or 4.17.3 or later. As a temporary workaround, consider restricting access to the KDC server and limiting the use of the krb5 pac parse function until a patch is available.

Exploit

Fix

DoS

RCE

Integer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2022:8637
ALSA-2022:8638
ALT-PU-2022-3106
ALT-PU-2022-3210
ALT-PU-2022-3222
ALT-PU-2022-3243
ALT-PU-2022-3298
ALT-PU-2024-14683
ALT-PU-2024-2315
AZL-12123
AZL-12133
AZL-37017
BDU:2022-06933
CESA-2022_8638
CESA-2022_8640
CVE-2022-42898
DLA-3206-1
DLA-3213-1
DSA-5286-1
DSA-5287-1
GHSA-64MQ-FVFJ-5X3C
JLSEC-2026-91
MGASA-2022-0467
MGASA-2022-0468
MGASA-2023-0010
OESA-2022-2121
OPENSUSE-SU-2022_4153-1
OPENSUSE-SU-2022_4167-1
OPENSUSE-SU-2022_4395-1
OPENSUSE-SU-2023:0019-1
OPENSUSE-SU-2023:0020-1
OPENSUSE-SU-2023_0160-1
OPENSUSE-SU-2024:12524-1
OPENSUSE-SU-2024:12525-1
OPENSUSE-SU-2024:12580-1
RHSA-2022:8637
RHSA-2022:8638
RHSA-2022:8639
RHSA-2022:8640
RHSA-2022:8641
RHSA-2022:8648
RHSA-2022:8662
RHSA-2022:8663
RHSA-2022:8669
RHSA-2022:9029
RHSA-2022_8637
RHSA-2022_8638
RHSA-2022_8640
RHSA-2022_8663
RLSA-2022:8637
RLSA-2022:8638
ROSA-SA-2024-2419
ROSA-SA-2024-2492
SUSE-SU-2022:4153-1
SUSE-SU-2022:4154-1
SUSE-SU-2022:4155-1
SUSE-SU-2022:4167-1
SUSE-SU-2022:4335-1
SUSE-SU-2022:4395-1
SUSE-SU-2022_4153-1
SUSE-SU-2022_4155-1
SUSE-SU-2022_4167-1
SUSE-SU-2022_4335-1
SUSE-SU-2023:0081-1
SUSE-SU-2023:0160-1
SUSE-SU-2023:0198-1
SUSE-SU-2023_0198-1
USN-5800-1
USN-5822-1
USN-5822-2
USN-5828-1
USN-5936-1
USN-7582-1
USN-7582-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Freebsd
Linuxmint
Mit Kerberos 5
Red Hat
Rocky Linux
Samba
Suse
Ubuntu