Vulnerability record · CVE-2022-41916 · published 15 November 2022
CVE-2022-41916: Heimdal project heimdal vulnerability
Heimdal Project · Heimdal
Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) and kinit (via PKINIT), as well as any third-party applications using Heimdal's libhx509. Users should upgrade to Heimdal 7.7.1 or 7.8. There are no known workarounds for this issue.
Description
Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) and kinit (via PKINIT), as well as any third-party applications using Heimdal's libhx509. Users should upgrade to Heimdal 7.7.1 or 7.8. There are no known workarounds for this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/heimdal/heimdal/security/advisories/GHSA-mgqr-gvh6-23cx | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/11/msg00034.html | Mailing ListThird Party Advisory |
| https://security.gentoo.org/glsa/202310-06 | |
| https://security.netapp.com/advisory/ntap-20230216-0008/ | |
| https://www.debian.org/security/2022/dsa-5287 | Third Party Advisory |
| https://github.com/heimdal/heimdal/security/advisories/GHSA-mgqr-gvh6-23cx | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/11/msg00034.html | Mailing ListThird Party Advisory |
| https://security.gentoo.org/glsa/202310-06 | |
| https://security.netapp.com/advisory/ntap-20230216-0008/ | |
| https://www.debian.org/security/2022/dsa-5287 | Third Party Advisory |
Track CVE-2022-41916 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-41916), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.