Vulnerability record · CVE-2022-3515 · published 12 January 2023
CVE-2022-3515: Gnupg libksba integer overflow vulnerability
Gnupg · Libksba
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
Description
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3515 | PatchThird Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2135610 | ExploitIssue TrackingThird Party Advisory |
| https://dev.gnupg.org/rK4b7d9cd4a018898d7714ce06f3faf2626c14582b | ExploitPatchThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20230706-0008/ | |
| https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html | Third Party Advisory |
| https://access.redhat.com/security/cve/CVE-2022-3515 | PatchThird Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2135610 | ExploitIssue TrackingThird Party Advisory |
| https://dev.gnupg.org/rK4b7d9cd4a018898d7714ce06f3faf2626c14582b | ExploitPatchThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20230706-0008/ | |
| https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html | Third Party Advisory |
Track CVE-2022-3515 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-3515), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.