PT-2023-4551 · Openssl+11 · Openssl+11

Matt Caswell

+2

·

Published

2023-07-13

·

Updated

2025-11-28

·

CVE-2023-3446

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 41.0.3
Description The issue is related to the functions DH check(), DH check ex(), and EVP PKEY param check() in the OpenSSL library. These functions can cause long delays when checking excessively long DH keys or parameters, potentially leading to a Denial of Service (DoS) attack if the key or parameters are obtained from an untrusted source. The DH check() function performs various checks on DH parameters, including confirming that the modulus (p parameter) is not too large. However, trying to use a very large modulus is slow, and OpenSSL will not normally use a modulus over 10,000 bits in length. The OpenSSL SSL/TLS implementation and the OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.
Recommendations To resolve the issue, update to OpenSSL version 41.0.3 or later. As a temporary workaround, consider restricting the use of the DH check(), DH check ex(), and EVP PKEY param check() functions to minimize the risk of exploitation. Avoid using the p parameter with large modulus values in the affected functions until the issue is resolved.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:7877
ALSA-2024:0888
ALSA-2024:2264
ALSA-2024:2447
ALT-PU-2023-4667
ALT-PU-2023-5983
ALT-PU-2023-6235
ALT-PU-2023-6294
ALT-PU-2023-6410
ALT-PU-2024-11974
ALT-PU-2025-1127
ALT-PU-2025-1184
AZL-42955
AZL-47646
BDU:2023-04957
BDU:2023-04960
CESA-2023_7877
CESA-2024_0888
CVE-2023-3446
DLA-3530-1
INFSA-2024_2264
INFSA-2024_2447
MGASA-2023-0253
MGASA-2023-0273
OESA-2023-1466
OESA-2024-1222
OESA-2024-1223
OESA-2024-1224
OESA-2024-1225
OESA-2024-1227
OESA-2024-1238
OPENSUSE-SU-2023_2962-1
OPENSUSE-SU-2023_2965-1
OPENSUSE-SU-2023_3011-1
OPENSUSE-SU-2023_3013-1
OPENSUSE-SU-2023_3093-1
OPENSUSE-SU-2024:13064-1
OPENSUSE-SU-2024:13065-1
OPENSUSE-SU-2024:13070-1
RHSA-2023:7622
RHSA-2023:7625
RHSA-2023:7877
RHSA-2023_7877
RHSA-2024:0154
RHSA-2024:0208
RHSA-2024:0408
RHSA-2024:0888
RHSA-2024:1415
RHSA-2024:2264
RHSA-2024:2447
RHSA-2024_0888
RHSA-2024_2264
RHSA-2024_2447
RLSA-2024:2264
ROSA-SA-2024-2366
SUSE-SU-2023:2961-1
SUSE-SU-2023:2962-1
SUSE-SU-2023:2964-1
SUSE-SU-2023:2965-1
SUSE-SU-2023:2972-1
SUSE-SU-2023:2973-1
SUSE-SU-2023:3011-1
SUSE-SU-2023:3012-1
SUSE-SU-2023:3013-1
SUSE-SU-2023:3093-1
SUSE-SU-2023:3096-1
SUSE-SU-2023:3160-1
SUSE-SU-2023:3179-1
SUSE-SU-2023_2961-1
SUSE-SU-2023_2962-1
SUSE-SU-2023_2964-1
SUSE-SU-2023_2965-1
SUSE-SU-2023_2972-1
SUSE-SU-2023_2973-1
SUSE-SU-2023_3011-1
SUSE-SU-2023_3012-1
SUSE-SU-2023_3013-1
SUSE-SU-2023_3093-1
SUSE-SU-2023_3096-1
SUSE-SU-2023_3160-1
SUSE-SU-2023_3179-1
USN-6435-1
USN-6435-2
USN-6450-1
USN-6709-1
USN-7018-1
USN-7894-1
USN-7894-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Ibm Aix
Linuxmint
Openssl
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu