UBUNTU-CVE-2022-39028

    Dashboard / Vulnerabilities / UBUNTU-CVE-2022-39028

    UBUNTU-CVE-2022-39028

    Published: 30 Aug 2022Last Modified: 4 Feb 2026

    Summary:

    Details: telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval, the telnet service would become unavailable after inetd logs a "telnet/tcp server failing (looping), service terminated" error. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.

    Affected packages

    Package

    Name: inetutils

    Purl: pkg:deb/ubuntu/inetutils@2:1.9.2-1ubuntu0.1~esm2?arch=source&distro=esm-infra-legacy/trusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2:1.9.2-1ubuntu0.1~esm2

    Affected versions

    2:1.9.1.306-0a482-1
    2:1.9.1.363-bbc1-1
    2:1.9.2-1
    2:1.9.2-1ubuntu0.1~esm1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    UBUNTU-CVE-2022-39028 | CVE-DB