QID 38874

Date Published: 2022-07-11

QID 38874: OpenSSL Heap Memory Corruption Vulnerability

The OpenSSL Project is an Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS) protocols as well as a general purpose cryptography library.

The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation..

Affected Versions:
OpenSSL version 3.0.4

Successful exploitation of this vulnerability may allow an remote attacker to corrupt memory and gain remote code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Please refer OpenSSL Advisory to obtain more information.
    Vendor References

    CVEs related to QID 38874

    Software Advisories
    Advisory ID Software Component Link
    OpenSSL Advisory URL Logo www.openssl.org/news/secadv/20220705.txt