VDB

ALPINE-CVE-2022-45142

ALPINE-CVE-2022-45142 PUBLISHED CVSS 7.5 HIGH

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Alpine:v3.21heimdal7.7.0-r0, 1.5.2-r7, 1.5.2-r8
Alpine:v3.15heimdal7.7.0-r8, 7.7.0-r7, 7.7.0-r6
Alpine:v3.18heimdal1.3.1-r2, 0, 1.2.1-r0
Alpine:v3.16heimdal7.7.0-r5, 7.7.0-r6, 7.7.0-r7
Alpine:v3.19heimdal0, 1.2.1-r1, 1.2.1-r4
Alpine:v3.14heimdal7.7.1-r0, 7.7.0-r4, 7.7.0-r3
Alpine:v3.23heimdal1.5.3-r0, 1.5.2-r8, 1.5.2-r7
Alpine:v3.22heimdal7.7.0-r1, 7.7.0-r3, 7.7.0-r4
Alpine:v3.20heimdal7.8.0-r1, 7.8.0-r0, 7.7.1-r0
Alpine:v3.17heimdal1.2.1-r3, 1.2.1-r4, 1.3.1-r1

Timeline

  • Mar 6, 2023 CVE Published
  • Dec 3, 2025 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›