CVE-2022-39028
published 2022-08-30CVE-2022-39028: telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.66%
74.0th percentile
telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval, the telnet service would become unavailable after inetd logs a "telnet/tcp server failing (looping), service terminated" error. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | inetutils | < inetutils 2:2.3-5 (bookworm) | inetutils 2:2.3-5 (bookworm) |
| gnu | inetutils | <= 2.3 | — |
| gnu | inetutils | >= 0 < 2:2.0-1+deb11u1 | 2:2.0-1+deb11u1 |
| gnu | inetutils | >= 0 < 2:2.3-5 | 2:2.3-5 |
| gnu | inetutils | >= 0 < 2:2.3-5 | 2:2.3-5 |
| gnu | inetutils | >= 0 < 2:2.3-5 | 2:2.3-5 |
| gnu | inetutils | >= 0 < 2:1.9.4-11ubuntu0.2 | 2:1.9.4-11ubuntu0.2 |
| gnu | inetutils | >= 0 < 2:2.2-2ubuntu0.1 | 2:2.2-2ubuntu0.1 |
| gnu | inetutils | >= 0 < 2:1.9.2-1ubuntu0.1~esm2 | 2:1.9.2-1ubuntu0.1~esm2 |
| gnu | inetutils | >= 0 < 2:1.9.4-1ubuntu0.1~esm3 | 2:1.9.4-1ubuntu0.1~esm3 |
| gnu | inetutils | >= 0 < 2:1.9.4-3ubuntu0.1+esm2 | 2:1.9.4-3ubuntu0.1+esm2 |
| mit | kerberos_5 | <= 1.0.3 | — |
| netkit-telnet_project | netkit-telnet | <= 0.17 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Inetutils vulnerabilities
vendor_ubuntu·2025-09-28·CVSS 7.8
CVE-2022-39028 [HIGH] Inetutils vulnerabilities
Title: Inetutils vulnerabilities
Summary: Several security issues were fixed in Inetutils.
Matthew Hickey discovered that Inetutils did not correctly handle certain
escape characters. An attacker could possibly use this issue to cause a
denial of service. (CVE-2019-0053)
It was discovered that Inetutils did not correctly handle certain memory
operations. An attacker could possibly use this issue to execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-10188)
It was discovered that Inetutils did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial of
service. (CVE-2022-39028)
It was discovered that Inetutils did not check the return values of set*id
functions. An attacker could possibly use this issue to esca
Ubuntu
Inetutils vulnerabilities
vendor_ubuntu·2023-08-22·CVSS 7.5
CVE-2022-39028 [HIGH] Inetutils vulnerabilities
Title: Inetutils vulnerabilities
Summary: Inetutils could be made to crash or execute arbitrary code.
It was discovered that telnetd in GNU Inetutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash. This issue
only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS (CVE-2022-39028)
It was discovered that Inetutils incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information,
or execute arbitrary code.
(CVE-2023-40303)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
krb5-appl: NULL pointer dereference
vendor_redhat·2022-08-30·CVSS 7.5
CVE-2022-39028 [HIGH] CWE-476 krb5-appl: NULL pointer dereference
krb5-appl: NULL pointer dereference
telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval, the telnet service would become unavailable after inetd logs a "telnet/tcp server failing (looping), service terminated" error. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.
A flaw was found in MIT krb5-appl, where it has a NULL pointer dereference
Debian
CVE-2022-39028: inetutils - telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivativ...
vendor_debian·2022·CVSS 7.5
CVE-2022-39028 [HIGH] CVE-2022-39028: inetutils - telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivativ...
telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval, the telnet service would become unavailable after inetd logs a "telnet/tcp server failing (looping), service terminated" error. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.
Scope: local
bookworm: resolved (fixed in 2:2.3-5)
bullseye: resolved (fixed in 2:2.0-1+deb11u1)
forky: resolved
OSV
inetutils vulnerabilities
osv·2025-09-28·CVSS 7.8
CVE-2019-0053 [HIGH] inetutils vulnerabilities
inetutils vulnerabilities
Matthew Hickey discovered that Inetutils did not correctly handle certain
escape characters. An attacker could possibly use this issue to cause a
denial of service. (CVE-2019-0053)
It was discovered that Inetutils did not correctly handle certain memory
operations. An attacker could possibly use this issue to execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-10188)
It was discovered that Inetutils did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial of
service. (CVE-2022-39028)
It was discovered that Inetutils did not check the return values of set*id
functions. An attacker could possibly use this issue to escalate their
privileges. (CVE-2023-40303)
OSV
inetutils vulnerabilities
osv·2023-08-22·CVSS 7.5
CVE-2022-39028 [HIGH] inetutils vulnerabilities
inetutils vulnerabilities
It was discovered that telnetd in GNU Inetutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash. This issue
only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS (CVE-2022-39028)
It was discovered that Inetutils incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information,
or execute arbitrary code.
(CVE-2023-40303)
GHSA
GHSA-jq82-jqvw-64w3: telnetd in GNU Inetutils through 2
ghsa_unreviewed·2022-08-31
CVE-2022-39028 [HIGH] CWE-476 GHSA-jq82-jqvw-64w3: telnetd in GNU Inetutils through 2
telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval, the telnet service would become unavailable after inetd logs a "telnet/tcp server failing (looping), service terminated" error. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.
OSV
CVE-2022-39028: telnetd in GNU Inetutils through 2
osv·2022-08-30·CVSS 7.5
CVE-2022-39028 [HIGH] CVE-2022-39028: telnetd in GNU Inetutils through 2
telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval, the telnet service would become unavailable after inetd logs a "telnet/tcp server failing (looping), service terminated" error. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.hadrons.org/cgit/debian/pkgs/inetutils.git/commit/?id=113da8021710d871c7dd72d2a4d5615d42d64289https://lists.debian.org/debian-lts-announce/2022/11/msg00033.htmlhttps://lists.gnu.org/archive/html/bug-inetutils/2022-08/msg00002.htmlhttps://pierrekim.github.io/blog/2022-08-24-2-byte-dos-freebsd-netbsd-telnetd-netkit-telnetd-inetutils-telnetd-kerberos-telnetd.htmlhttps://git.hadrons.org/cgit/debian/pkgs/inetutils.git/commit/?id=113da8021710d871c7dd72d2a4d5615d42d64289https://lists.debian.org/debian-lts-announce/2022/11/msg00033.htmlhttps://lists.gnu.org/archive/html/bug-inetutils/2022-08/msg00002.htmlhttps://pierrekim.github.io/blog/2022-08-24-2-byte-dos-freebsd-netbsd-telnetd-netkit-telnetd-inetutils-telnetd-kerberos-telnetd.html
2022-08-30
Published