Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2022-42898

Published: 25 December 2022

PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."

Notes

AuthorNote
mdeslaur
Per upstream Samba advisory, this is only an issue on 32-bit
systems.
rodrigo-zaiden
a regression in heimdal was reported by samba and fixed in
https://github.com/heimdal/heimdal/pull/1025
mdeslaur
See samba bug for samba regression fix not yet commited
The focal samba update was temporarily reverted by USN 5822-2
because it introduced regressions. It was later updated again
with USN 5936-1.

Priority

Medium

Cvss 3 Severity Score

8.8

Score breakdown

Status

Package Release Status
heimdal
Launchpad, Ubuntu, Debian
bionic
Released (7.5.0+dfsg-1ubuntu0.3)
focal
Released (7.7.0+dfsg-1ubuntu1.3)
jammy Needed

kinetic Ignored
(end of life, was needed)
lunar Ignored
(end of life, was needed)
mantic Needed

trusty
Released (1.6~git20131207+dfsg-1ubuntu1.2+esm3)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only)
upstream
Released (7.7.1, 7.8, 7.8.git20221115.a6cf945+dfsg-1)
xenial
Released (1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only)
Patches:
upstream: https://github.com/heimdal/heimdal/commit/b90b219ab8faa6bb0e7c2e7aa241aa7eeab0adac
upstream: https://github.com/heimdal/heimdal/commit/0c56257bdac80da015878fffdb0f8a42b8d73246
upstream: https://github.com/heimdal/heimdal/commit/9d1bfab9882d0aa14ae0981e6667c93db93ffc5d









Binaries built from this source package are in Universe and so are supported by the community.
krb5
Launchpad, Ubuntu, Debian
bionic
Released (1.16-2ubuntu0.3)
focal
Released (1.17-6ubuntu4.2)
jammy
Released (1.19.2-2ubuntu0.1)
kinetic
Released (1.20-1ubuntu0.1)
lunar Not vulnerable
(1.20.1-1build1)
mantic Not vulnerable
(1.20.1-1build1)
trusty
Released (1.12+dfsg-2ubuntu5.4+esm3)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only)
upstream
Released (1.20.1-1, 1.20.1, 1.19.4)
xenial
Released (1.13.2+dfsg-5ubuntu2.2+esm3)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only)
Patches:



upstream: https://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583
upstream: https://github.com/krb5/krb5/commit/b99de751dd35360c0fccac74a40f4a60dbf1ceea
upstream: https://github.com/krb5/krb5/commit/4e661f0085ec5f969c76c0896a34322c6c432de4






Binaries built from this source package are in Universe and so are supported by the community.
samba
Launchpad, Ubuntu, Debian
bionic Needed

focal
Released (2:4.15.13+dfsg-0ubuntu0.20.04.1)
jammy
Released (2:4.15.13+dfsg-0ubuntu1)
kinetic
Released (2:4.16.8+dfsg-0ubuntu1)
lunar Not vulnerable
(2:4.17.3+dfsg-3ubuntu1)
mantic Not vulnerable
(2:4.17.3+dfsg-3ubuntu1)
trusty Needed

upstream
Released (2:4.17.3+dfsg-1,4.17.3,4.16.7,4.15.12)
xenial Needs triage

Patches:






upstream: https://git.samba.org/?p=samba.git;a=commit;h=a8ef840d4362d3ffeab13c1d5fea417511b727c2
upstream: https://git.samba.org/?p=samba.git;a=commit;h=8369aee33a0b3de10485dc72223f4653585e3a79
upstream: https://git.samba.org/?p=samba.git;a=commit;h=f792d3e3906414d836d186ec279586c13a83ba8d
upstream: https://git.samba.org/?p=samba.git;a=commit;h=9c909c57ce7abacd96ba18173a9dc4ba9a7c0230
upstream: https://git.samba.org/?p=samba.git;a=commit;h=a3816433ae971830c2b16b366b10283aeb5a87b5
upstream: https://git.samba.org/?p=samba.git;a=commit;h=f3672577a8e15b7937d0067a262d04df632dade9

Severity score breakdown

Parameter Value
Base score 8.8
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H