CVE-2022-2274
This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 47.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation. SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86_64 architecture are affected by this issue.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 47.05% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- openssl/openssl · netapp/snapcenter · netapp/h410c firmware · netapp/h300s firmware · netapp/h500s firmware · netapp/h700s firmware · netapp/h410s firmware
- Source
- openssl-security@openssl.org
References
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=4d8a88c134df634ba610ff8db1eb8478ac5fd345
- https://github.com/openssl/openssl/issues/18625Exploit, Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220715-0010/Third Party Advisory
- https://www.openssl.org/news/secadv/20220705.txtVendor Advisory
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=4d8a88c134df634ba610ff8db1eb8478ac5fd345
- https://github.com/openssl/openssl/issues/18625Exploit, Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220715-0010/Third Party Advisory
- https://www.openssl.org/news/secadv/20220705.txtVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.