Описание
Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output. The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy. Only x86-64 systems with AVX...
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.6+ only |
| esm-apps-legacy/xenial | not-affected | 3.6+ only |
| esm-apps/bionic | not-affected | 3.6+ only |
| esm-apps/xenial | not-affected | 3.6+ only |
| esm-infra/focal | not-affected | 3.6+ only |
| jammy | not-affected | 3.6+ only |
| noble | not-affected | 3.6+ only |
| questing | not-affected | 3.6+ only |
| upstream | not-affected | 3.6+ only |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | uses system openssl |
| esm-apps-legacy/xenial | not-affected | 3.6+ only |
| esm-apps/bionic | not-affected | 3.6+ only |
| esm-apps/focal | not-affected | uses system openssl |
| esm-apps/jammy | not-affected | 3.6+ only |
| esm-apps/noble | not-affected | uses system openssl |
| esm-apps/xenial | not-affected | 3.6+ only |
| esm-infra-legacy/trusty | not-affected | uses system openssl |
| jammy | not-affected | 3.6+ only |
| noble | not-affected | uses system openssl |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.6+ only |
| esm-infra-legacy/trusty | not-affected | 3.6+ only |
| esm-infra-legacy/xenial | not-affected | 3.6+ only |
| esm-infra/bionic | not-affected | 3.6+ only |
| esm-infra/focal | not-affected | 3.6+ only |
| esm-infra/xenial | not-affected | 3.6+ only |
| fips-preview/jammy | not-affected | 3.6+ only |
| fips-updates/bionic | not-affected | 3.6+ only |
| fips-updates/focal | not-affected | 3.6+ only |
| fips-updates/jammy | not-affected | 3.6+ only |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| fips-preview/jammy | not-affected | 3.6+ only |
| fips-updates/jammy | not-affected | 3.6+ only |
| fips-updates/noble | not-affected | 3.6+ only |
| jammy | DNE | |
| noble | DNE | |
| questing | DNE | |
| upstream | not-affected | 3.6+ only |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra/bionic | not-affected | 3.6+ only |
| jammy | DNE | |
| noble | DNE | |
| questing | DNE | |
| upstream | not-affected | 3.6+ only |
Показывать по
7.5 High
CVSS3
Связанные уязвимости
Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output. The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy. Only x86-64 systems with AVX...
Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output. The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy. Only x86-64 systems with AVX
Issue summary: Applications using AES-CFB128 encryption or decryption ...
Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not written to output. The vulnerable code path is only reached when processing partial blocks (when a previous call left an incomplete block and the current call provides fewer bytes than needed to complete it). Additionally, the input buffer must be positioned at a page boundary with the following page unmapped. CFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or ChaCha20-Poly1305 instead. For these reasons the issue was assessed as Low severity according to our Security Policy. Only x86-64 systems with ...
7.5 High
CVSS3