VDB
GCVE-110-CERTCC-2022-730793
GCVE-110-CERTCC-2022-730793
Advisory Published
### Overview
The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code path can cause the application to crash.
### Description
**CVE-2022-3116**
A flawed logical condition in lib/gssapi/spnego/accept_sec_context.c allows a malicious actor to remotely trigger a NULL pointer dereference using a crafted negTokenInit token.
### Impact
An attacker can use a specially crafted network packet to cause a vulnerable application to crash.
### Solution
The latest version of code in the Heimdal master branch fixes the issue. However, the current stable release 7.7.0 does not include the fix.
### Acknowledgements
Thanks to Internet Systems Consortium for reporting the vulnerability.
This document was written by Kevin Stephens.
Aliases
References
Browse GCVE Records
77,895 records in the GCVE database · Updated August 9, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.