CVE-2022-47629

Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
Affected Products (NVD)
VendorProductVersion
gnupglibksba
𝑥
< 1.6.3
debiandebian_linux
10.0
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libksba
bookworm
1.6.3-2
fixed
bullseye
1.5.0-3+deb11u2
fixed
bullseye (security)
1.5.0-3+deb11u2
fixed
sid
1.6.7-2
fixed
trixie
1.6.7-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libksba
bionic
Fixed 1.3.5-2ubuntu0.18.04.2
released
focal
Fixed 1.3.5-2ubuntu0.20.04.2
released
jammy
Fixed 1.6.0-2ubuntu0.2
released
kinetic
Fixed 1.6.0-3ubuntu1.1
released
lunar
Fixed 1.6.3-2
released
trusty
Fixed 1.3.0-3ubuntu0.14.04.2+esm2
released
xenial
Fixed 1.3.3-1ubuntu0.16.04.1+esm2
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libksba-devel
suse enterprise desktop 15 SP4
1.3.5-150000.4.6.1
fixed
suse enterprise desktop 15 SP5
1.3.5-150000.4.6.1
fixed
suse enterprise desktop 15 SP6
1.6.4-150600.1.2
fixed
suse enterprise desktop 15 SP7
1.6.4-150600.1.2
fixed
suse enterprise sap 15 SP1
1.3.5-150000.4.6.1
fixed
suse enterprise sap 15 SP2
1.3.5-150000.4.6.1
fixed
suse enterprise sap 15 SP3
1.3.5-150000.4.6.1
fixed
suse enterprise sap 15 SP4
1.3.5-150000.4.6.1
fixed
suse enterprise sap 15 SP5
1.3.5-150000.4.6.1
fixed
suse enterprise sap 15 SP6
1.6.4-150600.1.2
fixed
suse enterprise sap 15 SP7
1.6.4-150600.1.2
fixed
suse enterprise server 15 SP1
1.3.5-150000.4.6.1
fixed
suse enterprise server 15 SP2
1.3.5-150000.4.6.1
fixed
suse enterprise server 15 SP3
1.3.5-150000.4.6.1
fixed
suse enterprise server 15 SP4
1.3.5-150000.4.6.1
fixed
suse enterprise server 15 SP5
1.3.5-150000.4.6.1
fixed
suse enterprise server 15 SP6
1.6.4-150600.1.2
fixed
suse enterprise server 15 SP7
1.6.4-150600.1.2
fixed
libksba8
suse enterprise desktop 15 SP4
1.3.5-150000.4.6.1
fixed
suse enterprise desktop 15 SP5
1.3.5-150000.4.6.1
fixed
suse enterprise desktop 15 SP6
1.6.4-150600.1.2
fixed
suse enterprise desktop 15 SP7
1.6.4-150600.1.2
fixed
suse enterprise sap 15 SP1
1.3.5-150000.4.6.1
fixed
suse enterprise sap 15 SP2
1.3.5-150000.4.6.1
fixed
suse enterprise sap 15 SP3
1.3.5-150000.4.6.1
fixed
suse enterprise sap 15 SP4
1.3.5-150000.4.6.1
fixed
suse enterprise sap 15 SP5
1.3.5-150000.4.6.1
fixed
suse enterprise sap 15 SP6
1.6.4-150600.1.2
fixed
suse enterprise sap 15 SP7
1.6.4-150600.1.2
fixed
suse enterprise server 15 SP1
1.3.5-150000.4.6.1
fixed
suse enterprise server 15 SP2
1.3.5-150000.4.6.1
fixed
suse enterprise server 15 SP3
1.3.5-150000.4.6.1
fixed
suse enterprise server 15 SP4
1.3.5-150000.4.6.1
fixed
suse enterprise server 15 SP5
1.3.5-150000.4.6.1
fixed
suse enterprise server 15 SP6
1.6.4-150600.1.2
fixed
suse enterprise server 15 SP7
1.6.4-150600.1.2
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libksba
RHEL 7
0:1.3.0-7.el7_9
fixed
RHEL 8
0:1.3.5-9.el8_7
fixed
RHEL 8.4 AUS
0:1.3.5-9.el8_4
fixed
RHEL 8.4 E4S
0:1.3.5-9.el8_4
fixed
RHEL 8.4 EUS
0:1.3.5-9.el8_4
fixed
RHEL 8.4 TUS
0:1.3.5-9.el8_4
fixed
RHEL 8.6 AUS
0:1.3.5-9.el8_6
fixed
RHEL 8.6 E4S
0:1.3.5-9.el8_6
fixed
RHEL 8.6 EUS
0:1.3.5-9.el8_6
fixed
RHEL 8.6 TUS
0:1.3.5-9.el8_6
fixed
RHEL 9
0:1.5.1-6.el9_1
fixed
libksba-devel
RHEL 7
0:1.3.0-7.el7_9
fixed
RHEL 8
0:1.3.5-9.el8_7
fixed
RHEL 8.4 AUS
0:1.3.5-9.el8_4
fixed
RHEL 8.4 E4S
0:1.3.5-9.el8_4
fixed
RHEL 8.4 EUS
0:1.3.5-9.el8_4
fixed
RHEL 8.4 TUS
0:1.3.5-9.el8_4
fixed
RHEL 8.6 AUS
0:1.3.5-9.el8_6
fixed
RHEL 8.6 E4S
0:1.3.5-9.el8_6
fixed
RHEL 8.6 EUS
0:1.3.5-9.el8_6
fixed
RHEL 8.6 TUS
0:1.3.5-9.el8_6
fixed
RHEL 9
0:1.5.1-6.el9_1
fixed