Excessive time spent checking invalid RSA public keys
Issue summary: Checking excessively long invalid RSA public keys may take a long time. Impact summary: Applications that use the function EVP_PKEY_public_check() to check RSA public keys may experience long delays. Where the key that is being checked has been obtained from an untrusted source this may lead to a Denial of Service. When function EVP_PKEY_public_check() is called on RSA public keys, a computation is done to confirm that the RSA modulus, n, is composite. For valid RSA keys, n is a product of two or more large primes and this computation completes quickly. However, if n is an overly large prime, then this computation would take a long time. An application that calls EVP_PKEY_public_check() and supplies an RSA key obtained from an untrusted source could be vulnerable to a Denial of Service attack. The function EVP_PKEY_public_check() is not called from other OpenSSL functions however it is called from the OpenSSL pkey command line application. For that reason that application is also vulnerable if used with the '-pubin' and '-check' options on untrusted data. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are affected by this issue.
- Yayın
- 25 Nis 2024
- Güncelleme
- 17 Haz 2026
- EPSS
- %2,3 · 83. yüzdelik
- CWE
- CWE-606
Takip etmek için giriş yap · Takip ettiğin kayıt KEV’e girer, istismarı çıkar ya da güncellenirse bildirim alırsın.
Rapor araçları
Aksiyon skoru
24
İzleyin
Şimdilik düşük öncelik.
- CVSS
- 23 / 40 · 5.9 / 10
- CISA KEV
- 0 / 30 · Listede değil
- EPSS
- 1 / 30 · %2,3
CISA SSVC kararı
- Sömürü
- yok
- Otomatikleştirilebilir
- hayır
- Teknik etki
- kısmi
Vulnrichment: CISA'nın karar ağacı girdileri.
Etkilenen sistemler
—
Üreticinin bildirdiği sürümler
Kaydı açan otorite (openssl) tarafından bildirilen etkilenen sürüm aralıkları. NVD'nin CPE analizinden bağımsızdır ve genellikle ondan önce gelir.
OpenSSL OpenSSL
- 3.0.0 ve sonrası · 3.0.13 öncesietkilenir · semver
- 3.1.0 ve sonrası · 3.1.5 öncesietkilenir · semver
- 3.2.0 ve sonrası · 3.2.1 öncesietkilenir · semver
Paket düzeyi etkilenme
OSV ve GitHub Advisory verisi: ekosistem, paket ve aralık. SBOM eşleşmesi bu tabloyu kullanır.
| Ekosistem | Paket | Etkilenen aralık | Düzeltme |
|---|---|---|---|
| AlmaLinux:9 | edk2-aarch64 | 20240524-6.el9_5 öncesi | 20240524-6.el9_5 |
| AlmaLinux:9 | edk2-ovmf | 20240524-6.el9_5 öncesi | 20240524-6.el9_5 |
| AlmaLinux:9 | edk2-tools | 20240524-6.el9_5 öncesi | 20240524-6.el9_5 |
| AlmaLinux:9 | edk2-tools-doc | 20240524-6.el9_5 öncesi | 20240524-6.el9_5 |
| AlmaLinux:9 | openssl | 1:3.0.7-27.el9 öncesi | 1:3.0.7-27.el9 |
| AlmaLinux:9 | openssl-devel | 1:3.0.7-27.el9 öncesi | 1:3.0.7-27.el9 |
| AlmaLinux:9 | openssl-libs | 1:3.0.7-27.el9 öncesi | 1:3.0.7-27.el9 |
| AlmaLinux:9 | openssl-perl | 1:3.0.7-27.el9 öncesi | 1:3.0.7-27.el9 |
| Alpine:v3.17 | openssl | 3.0.12-r3 öncesi | 3.0.12-r3 |
| Alpine:v3.18 | openssl | 3.1.4-r4 öncesi | 3.1.4-r4 |
| Debian:12 | openssl | 3.0.13-1~deb12u1 öncesi | 3.0.13-1~deb12u1 |
| Debian:13 | openssl | 3.1.5-1 öncesi | 3.1.5-1 |
| openSUSE:Tumbleweed | openssl-3 | 3.1.4-3.1 öncesi | 3.1.4-3.1 |
| Red Hat:enterprise_linux:9::appstream | edk2 | 0:20240524-6.el9_5 öncesi | 0:20240524-6.el9_5 |
| Red Hat:enterprise_linux:9::appstream | edk2-aarch64 | 0:20240524-6.el9_5 öncesi | 0:20240524-6.el9_5 |
| Red Hat:enterprise_linux:9::appstream | edk2-ovmf | 0:20240524-6.el9_5 öncesi | 0:20240524-6.el9_5 |
| Red Hat:enterprise_linux:9::appstream | openssl-debuginfo | 1:3.0.7-27.el9 öncesi | 1:3.0.7-27.el9 |
| Red Hat:enterprise_linux:9::appstream | openssl-debugsource | 1:3.0.7-27.el9 öncesi | 1:3.0.7-27.el9 |
| Red Hat:enterprise_linux:9::appstream | openssl-devel | 1:3.0.7-27.el9 öncesi | 1:3.0.7-27.el9 |
| Red Hat:enterprise_linux:9::appstream | openssl-libs-debuginfo | 1:3.0.7-27.el9 öncesi | 1:3.0.7-27.el9 |
| Red Hat:enterprise_linux:9::appstream | openssl-perl | 1:3.0.7-27.el9 öncesi | 1:3.0.7-27.el9 |
| Red Hat:enterprise_linux:9::baseos | openssl | 1:3.0.7-27.el9 öncesi | 1:3.0.7-27.el9 |
| Red Hat:enterprise_linux:9::baseos | openssl-libs | 1:3.0.7-27.el9 öncesi | 1:3.0.7-27.el9 |
| Red Hat:enterprise_linux:9::crb | edk2-debugsource | 0:20240524-6.el9_5 öncesi | 0:20240524-6.el9_5 |
+8
Aynı üründe
openssl: tüm kayıtlarAynı birincil ürünün en yüksek skorlu diğer kayıtları.
- CVE-2014-0160The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remKEV90Hemen
- CVE-2021-3711SM2 Decryption Buffer Overflow65Bu hafta
- CVE-2003-0545Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code 65Bu hafta
- CVE-2016-2108The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denia62Bu hafta
- CVE-2016-6309statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a den60Bu hafta
- CVE-2022-3786X.509 Email Address Variable Length Buffer Overflow58Planlayın
Düzeltme
Hangi sürüme geçmeli
Üretici, paket deposu ve Microsoft kayıtlarından derlenen düzeltme sürümleri. Yükseltmeden önce üreticinin notunu doğrulayın.
| Ürün / paket | Düzeltilmiş sürüm | Kaynak |
|---|---|---|
| OpenSSL OpenSSL | 3.0.13 | Üretici (CNA) |
| OpenSSL OpenSSL | 3.1.5 | Üretici (CNA) |
| OpenSSL OpenSSL | 3.2.1 | Üretici (CNA) |
| almalinux:edk2-aarch64 | 20240524-6.el9_5 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:edk2-ovmf | 20240524-6.el9_5 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:edk2-tools | 20240524-6.el9_5 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:edk2-tools-doc | 20240524-6.el9_5 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:openssl | 1:3.0.7-27.el9 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:openssl-devel | 1:3.0.7-27.el9 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:openssl-libs | 1:3.0.7-27.el9 · AlmaLinux:9 | Paket deposu (OSV) |
| almalinux:openssl-perl | 1:3.0.7-27.el9 · AlmaLinux:9 | Paket deposu (OSV) |
| alpine:openssl | 3.0.12-r3 · Alpine:v3.17 | Paket deposu (OSV) |
| debian:openssl | 3.0.13-1~deb12u1 · Debian:12 | Paket deposu (OSV) |
| opensuse:openssl-3 | 3.0.8-150500.5.24.1 · openSUSE:Leap 15.5 | Paket deposu (OSV) |
| red hat:edk2 | 0:20240524-6.el9_5 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:edk2-aarch64 | 0:20240524-6.el9_5 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:edk2-debugsource | 0:20240524-6.el9_5 · Red Hat:enterprise_linux:9::crb | Paket deposu (OSV) |
| red hat:edk2-ovmf | 0:20240524-6.el9_5 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:edk2-tools | 0:20240524-6.el9_5 · Red Hat:enterprise_linux:9::crb | Paket deposu (OSV) |
| red hat:openssl | 1:3.0.7-27.el9 · Red Hat:enterprise_linux:9::baseos | Paket deposu (OSV) |
| red hat:openssl-debuginfo | 1:3.0.7-27.el9 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:openssl-debugsource | 1:3.0.7-27.el9 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:openssl-devel | 1:3.0.7-27.el9 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:openssl-libs | 1:3.0.7-27.el9 · Red Hat:enterprise_linux:9::baseos | Paket deposu (OSV) |
| red hat:openssl-libs-debuginfo | 1:3.0.7-27.el9 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| red hat:openssl-perl | 1:3.0.7-27.el9 · Red Hat:enterprise_linux:9::appstream | Paket deposu (OSV) |
| rocky linux:edk2 | 0:20240524-6.el9_5.3 · Rocky Linux:9 | Paket deposu (OSV) |
| suse:openssl-3 | 3.0.8-150500.5.24.1 · SUSE:Linux Enterprise Module for Basesystem 15 SP5 | Paket deposu (OSV) |
İstismar durumu
Bilinen kamuya açık istismar yok
Şu an kamuya açık bir istismar görülmedi. Bu, güvende olduğunuz anlamına gelmez; yalnızca eşiğin biraz daha yüksek olduğunu gösterir.
Araştırma bağlamı
Pentester ve araştırmacı için: saldırı profili, puan anlaşmazlığı, zaman çizelgesi, yama commit’leri, kredi, varyant ve zincir adayları, bug bounty kapsamı. Hepsi mevcut veriden türetilir; istismar kodu içermez.
Zaman çizelgesi
Yayından bugüne: kavram kanıtı, Metasploit modülü, CISA KEV ve düzeltme kaydı. Tarihler kaynakların bildirdiği tarihlerdir.
Yayın dışında tarihli olay yok.
FIRST EPSS günlük puanı; yalnızca 0,01 ve üstü değişimler kaydedilir (adım grafiği).
Yama ve commit bağlantıları
Referanslardaki commit, PR ve diff adresleri. Patch-diff ve varyant avı için başlangıç noktası; istismar değil, düzeltmedir.
Kredi
Tüm araştırmacılarCNA kaydında adı geçen bulan, bildiren ve analistler. Ada tıkla, aynı araştırmacının diğer kayıtlarını gör.
- Tomas Mrazdüzeltme geliştirici
- OSS-Fuzzbulan
Varyant adayları
Aynı üründe aynı zafiyet sınıfı, 18 ay içinde. Yama kök nedeni kapatmadıysa kardeş hata burada olur.
- CVE-2023-3446281 gün araylaExcessive time spent checking DH keys and parameters23İzleyin
- CVE-2023-5678171 gün araylaExcessive time spent in DH check / generation with large Q parameter value22İzleyin
- CVE-2023-3817269 gün araylaExcessive time spent checking DH q parameter value22İzleyin
- CVE-2024-460321 gün araylaExcessive time spent checking DSA keys and parameters21İzleyin
Zincir adayları
Aynı üründe kimlik doğrulama atlatma ile yetki isteyen bir açık kısa aralıkla yayımlanmış: birlikte kimlik doğrulamasız bir yola dönüşebilir.
—
Bug bounty kapsamı
Bilinen herkese açık program yok.
Kaynak: bounty-targets-data (HackerOne, Bugcrowd, Intigriti, YesWeHack herkese açık listeleri).
Teknik detay
Saldırı koşulları
- İnternetten erişebilen herkes tetikleyebilir.
- Hesap ya da parola gerekmez.
- Kullanıcının bir şey yapması gerekmez.
- Zamanlama ya da yapılandırma gibi özel koşullar gerekir.
Başarılı olursa
- Gizlilik
- yok
- Bütünlük
- yok
- Erişilebilirlik
- yüksek · hizmet durdurulabilir
- Saldırı vektörü
- Ağ
- Karmaşıklık
- Yüksek
- Gereken yetki
- Yok
- Kullanıcı etkileşimi
- Gerekmez
- Kapsam
- Değişmez
- Gizlilik etkisi
- Yok
- Bütünlük etkisi
- Yok
- Erişilebilirlik etkisi
- Yüksek
Zayıflık sınıfı (CWE)
CWE-606 · Unchecked Input for Loop ConditionCVSS vektörü
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd-secondary
Saldırı bağlamı
Bu zafiyet sınıfının (CWE) MITRE CAPEC saldırı desenleri ve ATT&CK teknikleri. Tespit kuralı ve tehdit avı için başlangıç noktası.
Bu CWE için MITRE'de CAPEC/ATT&CK eşlemesi yok.
Noroxi analizi
Bu kayıt için henüz Noroxi analizi yok
385 binden fazla zafiyetin tamamına elle analiz yazmıyoruz; bu dürüst olmazdı. Öne çıkan ve sahada etkisi olan zafiyetler için mekanizma, tespit ve kapatma adımlarını ekibimiz yazıyor.
Bu ürünü kullanıyoruz, yardım isteyinDeğişiklik günlüğü
- Düzeltme✗ → ✓
Takip ettiğiniz kayıtlarda bu değişiklikler bildirim olarak da gelir. →
Referanslar
- github.com/openssl/openssl/commit/0b0f7abfb37350794a4b8960fafc292cd5d1b84d
- github.com/openssl/openssl/commit/18c02492138d1eb8b6548cb26e7b625fb2414a2a
- github.com/openssl/openssl/commit/a830f551557d3d66a84bbb18a5b889c640c36294
- www.openssl.org/news/secadv/20240115.txt
- www.openwall.com/lists/oss-security/2024/03/11/1
- security.netapp.com/advisory/ntap-20240531-0007/
- cert-portal.siemens.com/productcert/html/ssa-265688.html
- cert-portal.siemens.com/productcert/html/ssa-331112.html
- cert-portal.siemens.com/productcert/html/ssa-769027.html
- cert-portal.siemens.com/productcert/html/ssa-915275.html
Üretici bildirimleri ve resmî kayıtlar. İstismar/PoC bağlantıları bilinçli olarak dışarıda bırakıldı.