Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3996

Опубликовано: 13 дек. 2022
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the -policy' argument to the command line utilities or by calling the X509_VERIFY_PARAM_set1_policies()' function. Update (31 March 2023): The description of the policy processing enablement was corrected based on CVE-2023-0466.

A vulnerability was found in OpenSSL. This security flaw occurs if an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows), this issue results in a denial of service when the affected process hangs. Policy processing enabled on a publicly-facing server is not considered a standard setup. Policy processing is enabled by passing the -policy' argument to the command line utilities or by calling either the X509_VERIFY_PARAM_add0_policy()' or `X509_VERIFY_PARAM_set1_policies()' functions.

Отчет

This CVE is marked as Not Affected for all Red Hat Products because the problem caused by this CVE (deadlock, potential DDoS) is platform-specific. Thread management implementation works well for Linux but causes deadlocks on Windows systems only.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6opensslNot affected
Red Hat Enterprise Linux 7opensslNot affected
Red Hat Enterprise Linux 7ovmfNot affected
Red Hat Enterprise Linux 8compat-openssl10Not affected
Red Hat Enterprise Linux 8edk2Not affected
Red Hat Enterprise Linux 8opensslNot affected
Red Hat Enterprise Linux 8shimNot affected
Red Hat Enterprise Linux 9compat-openssl11Not affected
Red Hat Enterprise Linux 9edk2Not affected
Red Hat Enterprise Linux 9opensslNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-609
https://bugzilla.redhat.com/show_bug.cgi?id=2153239openssl: double locking leads to denial of service

EPSS

Процентиль: 39%
0.00172
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function. Update (31 March 2023): The description of the policy processing enablement was corrected based on CVE-2023-0466.

CVSS3: 7.5
nvd
около 3 лет назад

If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function. Update (31 March 2023): The description of the policy processing enablement was corrected based on CVE-2023-0466.

CVSS3: 7.5
msrc
больше 1 года назад

X.509 Policy Constraints Double Locking

CVSS3: 7.5
debian
около 3 лет назад

If an X.509 certificate contains a malformed policy constraint and pol ...

CVSS3: 7.5
github
около 3 лет назад

Denial of service by double-checked locking in openssl-src

EPSS

Процентиль: 39%
0.00172
Низкий

5.3 Medium

CVSS3