CVE-2023-1255
Summary
| CVE | CVE-2023-1255 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-20 17:15:00 UTC |
| Updated | 2023-09-08 17:15:00 UTC |
| Description | Issue summary: The AES-XTS cipher decryption implementation for 64 bit ARM platform contains a bug that could cause it to read past the input buffer, leading to a crash. Impact summary: Applications that use the AES-XTS algorithm on the 64 bit ARM platform can crash in rare circumstances. The AES-XTS algorithm is usually used for disk encryption. The AES-XTS cipher decryption implementation for 64 bit ARM platform will read past the end of the ciphertext buffer if the ciphertext size is 4 mod 5 in 16 byte blocks, e.g. 144 bytes or 1024 bytes. If the memory after the ciphertext buffer is unmapped, this will trigger a crash which results in a denial of service. If an attacker can control the size and location of the ciphertext buffer being decrypted by an application using AES-XTS on 64 bit ARM, the application is affected. This is fairly unlikely making this issue a Low severity one. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.openssl.org Git - openssl.git/commitdiff | MISC | git.openssl.org | |
| CVE-2023-1255 OpenSSL Vulnerability in NetApp Products | NetApp Product Security | MISC | security.netapp.com | |
| /err404.html | MISC | www.openssl.org | |
| git.openssl.org Git - openssl.git/commitdiff | MISC | git.openssl.org | |
| oss-security - OpenSSL Security Advisory | MISC | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160752 Oracle Enterprise Linux Security Update for Open Secure Sockets Layer (OpenSSL) (ELSA-2023-3722)
- 184876 Debian Security Update for Open Secure Sockets Layer (OpenSSL) (CVE-2023-1255)
- 199379 Ubuntu Security Notification for Open Secure Sockets Layer (OpenSSL) Vulnerabilities (USN-6119-1)
- 241736 Red Hat Update for Open Secure Sockets Layer (OpenSSL) (RHSA-2023:3722)
- 355167 Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : ALAS2023-2023-181
- 379141 SolarWinds Serv-U HTML Injection Vulnerability
- 502981 Alpine Linux Security Update for openssl3
- 502989 Alpine Linux Security Update for Open Secure Sockets Layer (OpenSSL)
- 503120 Alpine Linux Security Update for openssl
- 505905 Alpine Linux Security Update for openssl
- 941150 AlmaLinux Security Update for Open Secure Sockets Layer (OpenSSL) (ALSA-2023:3722)