CVE-2022-42898 is a critical integer overflow vulnerability in the PAC parsing component of MIT Kerberos 5 and Heimdal, affecting versions before 1.19.4/1.20.1 and 7.7.1 respectively, as well as related Samba products. This flaw can lead to remote code execution on 32-bit platforms due to a resultant heap-based buffer overflow, and denial of service on other platforms. With a CVSS score of 8.8 (HIGH), it is easily exploitable over the network with low privileges and no user interaction, potentially granting full confidentiality, integrity, and availability impact. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not listed in CISA's KEV catalog, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.8, < 1.19.4CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:* | ||
1.20CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.20:-:*:*:*:*:*:* | ||
1.20CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.20:beta1:*:*:*:*:*:* | ||
< 7.7.1CPE matchmatch criteria | cpe:2.3:a:heimdal_project:heimdal:*:*:*:*:*:*:*:* | ||
< 4.15.12CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk User Behavior Analytics (UBA) - July 2025
Jul 30, 2025CVE-2022-42898
Oct 8, 2024AS-2022-016: Samba
Dec 27, 2022PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC kadmind or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow) and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."
Dec 13, 2022krb5: integer overflow vulnerabilities in PAC parsing
Nov 15, 2022