CVE-2022-3515
NixOS vulnerability analysis and mitigation

Overview

CVE-2022-3515 is a critical vulnerability discovered in the Libksba library, which is used by GnuPG for parsing ASN.1 structures in S/MIME. The vulnerability was discovered in October 2022 and affects all versions of Libksba prior to 1.6.3. The flaw exists due to an integer overflow within the CRL parser, which can be exploited remotely through specially crafted data, such as malicious S/MIME attachments (GnuPG Blog).

Technical details

The vulnerability stems from an integer overflow in the _ksba_ber_read_tl function, which parses tag-length-value objects. The issue occurs when processing the sum of header length and announced length of the value, which can wrap around and bypass size checks, leading to buffer overflow conditions. The vulnerability received a CVSS v3.1 base score of 9.8 (CRITICAL) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating its severe nature (NVD).

Impact

Successful exploitation of this vulnerability could lead to remote code execution on the target system, disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). The vulnerability primarily affects gpgsm (the S/MIME component of GnuPG) and dirmngr, which handles Certificate Revocation Lists (CRLs) and TLS certificate verification (GnuPG Blog, NetApp Advisory).

Mitigation and workarounds

The vulnerability was fixed in Libksba version 1.6.3. Users on Unix or Linux systems should update to Libksba 1.6.3 or newer and restart any background processes. Windows users should update to Gpg4win version 4.1.0 or newer, GnuPG VS-Desktop version 3.1.26 or newer, GnuPG installer for Windows version 2.4.0, or GnuPG LTS installer for Windows version 2.2.41. As a temporary workaround for Windows systems, users can extract and replace the libksba-8.dll from the respective updated package (GnuPG Blog).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management