PT-2022-24791 · Wolfssl+1 · Wolfssl+1

Max

·

Published

2022-09-28

·

Updated

2025-05-20

·

CVE-2022-39173

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions wolfSSL versions prior to 5.5.1
Description The issue occurs when malicious clients cause a buffer overflow during a TLS 1.3 handshake, specifically when an attacker supposedly resumes a previous TLS session. This happens when a Hello Retry Request is triggered during the resumption Client Hello, and both Client Hellos contain a list of duplicate cipher suites. Two Client Hellos are required to trigger the buffer overflow: one in the resumed session and a second one as a response to a Hello Retry Request message.
Recommendations For versions prior to 5.5.1, update to version 5.5.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of TLS 1.3 handshake resumption to minimize the risk of exploitation. Avoid using duplicate cipher suites in Client Hellos until the issue is resolved.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2688
ALT-PU-2023-1034
CVE-2022-39173

Affected Products

Alt Linux
Wolfssl