PT-2022-3287 · Openssl · Openssl

Xi Ruoyao

·

Published

2022-07-01

·

Updated

2024-06-15

·

CVE-2022-2274

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 3.0.4
Description The issue is related to a serious bug in the RSA implementation for X86 64 CPUs supporting the AVX512IFMA instructions. This bug makes the RSA implementation with 2048 bit private keys incorrect on such machines, leading to memory corruption during computation. As a consequence of the memory corruption, an attacker may be able to trigger a remote code execution on the machine performing the computation. SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86 64 architecture are affected by this issue.
Recommendations For OpenSSL version 3.0.4, update to version 3.0.5 to fix the issue. As a temporary workaround, consider disabling the use of 2048 bit RSA private keys on machines supporting AVX512IFMA instructions of the X86 64 architecture until a patch is available. Restrict access to SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86 64 architecture to minimize the risk of exploitation.

Exploit

Fix

RCE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04023
CVE-2022-2274
GHSA-735F-PG76-FXC4
OPENSUSE-SU-2024:12204-1
OPENSUSE-SU-2024:12983-1
RUSTSEC-2022-0033

Affected Products

Openssl