CVE-2022-41916: Read one byte past a buffer when normalizing Unicode
Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) and kinit (via PKINIT), as well as any third-party applications using Heimdal's libhx509. Users should upgrade to Heimdal 7.7.1 or 7.8. There are no known workarounds for this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/heimdalto a version that resolves this vulnerability.Fixed in 7.5.0+dfsg-3+deb10u2Fixed in 7.7.0+dfsg-2+deb11u3Fixed in 7.8.git20221117.28daf24+dfsg-2Fixed in 7.8.git20221117.28daf24+dfsg-3 - Upgrade
Upgrade
Heimdalto a version that resolves this vulnerability.Fixed in 7.7.1 - Upgrade
Upgrade
Heimdalto a version that resolves this vulnerability.Fixed in 7.8
Event History
Frequently Asked Questions
What is CVE-2022-41916?
CVE-2022-41916 is a vulnerability in Heimdal's PKI certificate validation library that allows for a denial of service attack.
What versions of Heimdal are affected by CVE-2022-41916?
Versions prior to 7.7.1 of Heimdal are vulnerable to CVE-2022-41916.
How can I fix CVE-2022-41916?
To fix CVE-2022-41916, you should update to Heimdal version 7.7.1 or later.
What is the severity level of CVE-2022-41916?
CVE-2022-41916 has a severity level of high.
Where can I find more information about CVE-2022-41916?
More information about CVE-2022-41916 can be found at the following references: [link1](https://github.com/heimdal/heimdal/security/advisories/GHSA-mgqr-gvh6-23cx), [link2](https://github.com/heimdal/heimdal/commit/eb87af0c2d189c25294c7daf483a47b03af80c2c), [link3](https://security-tracker.debian.org/tracker/CVE-2022-41916).