Vulnerability record · CVE-2021-44758 · published 26 December 2022
CVE-2021-44758: Heimdal project heimdal null pointer dereference vulnerability
Heimdal Project · Heimdal
Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept.
Description
Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/heimdal/heimdal/commit/f9ec7002cdd526ae84fbacbf153162e118f22580 | PatchThird Party Advisory |
| https://github.com/heimdal/heimdal/security/advisories/GHSA-69h9-669w-88xv | Third Party Advisory |
| https://security.gentoo.org/glsa/202310-06 | |
| https://github.com/heimdal/heimdal/commit/f9ec7002cdd526ae84fbacbf153162e118f22580 | PatchThird Party Advisory |
| https://github.com/heimdal/heimdal/security/advisories/GHSA-69h9-669w-88xv | Third Party Advisory |
| https://security.gentoo.org/glsa/202310-06 |
Track CVE-2021-44758 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-44758), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.