PT-2023-5255 · Openssl+2 · Openssl+2

Bernd Edlinger

+1

·

Published

2023-09-08

·

Updated

2026-04-27

·

CVE-2023-4807

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description The POLY1305 MAC implementation in OpenSSL contains a bug that might corrupt the internal state of applications on the Windows 64 platform when running on newer X86 64 processors supporting the AVX512-IFMA instructions. If an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various application-dependent consequences. The consequences of this kind of internal application state corruption can be various, from no consequences to the worst consequences, where the attacker could get complete control of the application process. However, given the contents of the registers are just zeroized, the most likely consequence would be an incorrect result of some application-dependent calculations or a crash leading to a denial of service.
Recommendations As a workaround, the AVX512-IFMA instructions support can be disabled at runtime by setting the environment variable OPENSSL ia32cap: OPENSSL ia32cap=:~0x200000 At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-5753
ALT-PU-2023-5983
ALT-PU-2023-6235
ALT-PU-2023-6294
ALT-PU-2023-6410
ALT-PU-2024-11974
ALT-PU-2025-1127
ALT-PU-2025-1184
AZL-39646
AZL-78585
BDU:2023-05872
CVE-2023-4807
JLSEC-2026-242
OPENSUSE-SU-2024:13241-1
OPENSUSE-SU-2024:13275-1

Affected Products

Alt Linux
Openssl
Red Os