yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2021-44758
Component Overview
Vulnerability Overview
Name
CVE-2021-44758
Source
NVD (
link
)
Debian (
link
)
Description
Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept.
CWEs
CWE-476
CWE-476
Published Date
Dec 26, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/heimdal/heimdal/commit/f9ec7002cdd526ae84fbacbf153162e118f22580
Patch
https://github.com/heimdal/heimdal/security/advisories/GHSA-69h9-669w-88xv
Third Party Advisory
https://github.com/heimdal/heimdal/commit/f9ec7002cdd526ae84fbacbf153162e118f22580
Patch
https://github.com/heimdal/heimdal/security/advisories/GHSA-69h9-669w-88xv
Third Party Advisory
Analysis
#
Affected Component
Analysis
samba
Patched
Vulnerability Ratings
#
7.5
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
samba4
buildroot
2025.02.x
4.22.10
Not Affected
samba4
buildroot
master
4.24.3
Not Affected
samba4
openwrt
master
4.22.7-r3
Not Affected
samba4
openwrt
openwrt-25.12
4.22.7-r3
Not Affected
samba
yocto
master
4.23.5
Not Affected
samba
yocto
scarthgap
4.19.9
Not Affected
Resolved with patches
#
samba (yocto:kirkstone)
#
Title
Author
Resolve
1
spnego: CVE-2021-44758 send_reject when no mech selected
Nicolas Williams <nico@twosigma.com>
CVE-2021-44758