PT-2023-4554 · Openssl+11 · Openssl+11

Bernd Edlinger

+1

·

Published

2023-07-31

·

Updated

2026-04-27

·

CVE-2023-3817

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 3.0 OpenSSL versions prior to 3.1
Description The issue is related to the functions DH check(), DH check ex(), and EVP PKEY param check() in the OpenSSL library. These functions can cause excessive delays when checking excessively long DH keys or parameters, potentially leading to a Denial of Service attack if the key or parameters are obtained from an untrusted source. The DH check() function performs various checks on DH parameters, and a large q parameter value can trigger an overly long computation during some of these checks. The OpenSSL SSL/TLS implementation and the OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.
Recommendations For OpenSSL versions prior to 3.0, update to version 3.0 or later to resolve the issue. For OpenSSL versions prior to 3.1, update to version 3.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the DH check(), DH check ex(), and EVP PKEY param check() functions to minimize the risk of exploitation. Avoid using the dhparam and pkeyparam command line applications with the "-check" option until the issue is resolved.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:7877
ALSA-2024:2447
ALT-PU-2023-5983
ALT-PU-2023-6235
ALT-PU-2023-6294
ALT-PU-2023-6410
ALT-PU-2024-11974
ALT-PU-2025-1127
ALT-PU-2025-1184
AZL-27815
AZL-27817
AZL-31139
AZL-34669
AZL-35247
AZL-37764
BDU:2023-04960
CESA-2023_7877
CVE-2023-3817
DLA-3530-1
INFSA-2024_2447
JLSEC-2026-241
MGASA-2023-0253
MGASA-2023-0273
OESA-2023-1481
OPENSUSE-SU-2023_3242-1
OPENSUSE-SU-2023_3243-1
OPENSUSE-SU-2023_3244-1
OPENSUSE-SU-2023_3338-1
OPENSUSE-SU-2023_3397-1
OPENSUSE-SU-2023_4189-1
OPENSUSE-SU-2023_4190-1
OPENSUSE-SU-2024:13090-1
OPENSUSE-SU-2024:13097-1
OPENSUSE-SU-2024:13111-1
RHSA-2023:5931
RHSA-2023:7622
RHSA-2023:7625
RHSA-2023:7877
RHSA-2023_7877
RHSA-2024:0154
RHSA-2024:0208
RHSA-2024:2447
RHSA-2024_2447
ROSA-SA-2024-2366
SUSE-SU-2023:3239-1
SUSE-SU-2023:3242-1
SUSE-SU-2023:3243-1
SUSE-SU-2023:3244-1
SUSE-SU-2023:3244-2
SUSE-SU-2023:3291-1
SUSE-SU-2023:3291-2
SUSE-SU-2023:3308-1
SUSE-SU-2023:3338-1
SUSE-SU-2023:3339-1
SUSE-SU-2023:3397-1
SUSE-SU-2023:3958-1
SUSE-SU-2023:4189-1
SUSE-SU-2023:4190-1
SUSE-SU-2023_3239-1
SUSE-SU-2023_3242-1
SUSE-SU-2023_3243-1
SUSE-SU-2023_3244-1
SUSE-SU-2023_3291-2
SUSE-SU-2023_3308-1
SUSE-SU-2023_3338-1
SUSE-SU-2023_3339-1
SUSE-SU-2023_3397-1
SUSE-SU-2023_3958-1
SUSE-SU-2023_4189-1
SUSE-SU-2023_4190-1
USN-6435-1
USN-6435-2
USN-6450-1
USN-6709-1
USN-7894-1
USN-7894-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Ibm Aix
Linuxmint
Openssl
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu