Logo
vulnerabilityCVE-2022-45142
Name
CVE-2022-45142
Source
NVD ( link)Debian ( link)
Description
The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
samba
Patched

Vulnerability Ratings#


7.5
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
4.22.10
Not Affected
buildroot
master
4.24.3
Not Affected
openwrt
master
4.22.7-r3
Not Affected
openwrt
openwrt-25.12
4.22.7-r3
Not Affected
yocto
master
4.23.5
Not Affected
yocto
scarthgap
4.19.9
Not Affected

Resolved with patches#


samba (yocto:kirkstone)

#
Title
Author
Resolve
1
CVE-2022-45142: gsskrb5: fix accidental logic inversions
Helmut Grohne <helmut@...divi.de>
CVE-2022-45142