Описание
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
A flaw was found in Go's crypto/x509 package. A remote attacker could exploit this by presenting a specially crafted certificate chain containing a large number of policy mappings. This inefficient validation process consumes excessive resources, which can lead to a denial of service (DoS) for applications or systems performing certificate validation.
Отчет
This flaw occurs during the validation of otherwise trusted certificate chains that contain a large number of policy mappings, leading to excessive resource consumption. Exploitation requires an attacker to present a specially crafted, yet trusted, certificate chain which would require the attacker has already compromised a trusted certificate root. Red Hat continuously monitors certificate authorities and curates the set which is trusted by default for Red Hat products.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Assisted Installer for Red Hat OpenShift Container Platform 2 | redhat-user-workloads/appliance | Affected | ||
| Builds for Red Hat OpenShift | redhat-user-workloads/openshift-builds-waiter-1-6 | Not affected | ||
| Builds for Red Hat OpenShift | redhat-user-workloads/openshift-builds-waiter-1-7 | Not affected | ||
| cert-manager Operator for Red Hat OpenShift | redhat-user-workloads/jetstack-cert-manager-1-17 | Affected | ||
| cert-manager Operator for Red Hat OpenShift | redhat-user-workloads/jetstack-cert-manager-1-18 | Affected | ||
| Confidential Compute Attestation | redhat-user-workloads/osc-caa | Affected | ||
| Confidential Compute Attestation | redhat-user-workloads/trustee-operator | Affected | ||
| Deployment Validation Operator | redhat-user-workloads/deployment-validation-operator | Affected | ||
| ExternalDNS Operator | edo/external-dns-rhel8 | Affected | ||
| ExternalDNS Operator | edo/external-dns-rhel9 | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
Validating certificate chains which use policies is unexpectedly ineff ...
Moderate: golang-github-openprinting-ipp-usb security update
EPSS
5.9 Medium
CVSS3