PT-2023-5588 · Unknown+8 · Crypto/Tls+8

Mateusz Poliwczak

·

Published

2023-08-02

·

Updated

2025-09-29

·

CVE-2023-29409

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions crypto/tls (affected versions not specified)
Description The issue is related to extremely large RSA keys in certificate chains, which can cause a client/server to expend significant CPU time verifying signatures. With the fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but the target is the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:5738
ALSA-2023:7762
ALSA-2023:7763
ALSA-2023:7764
ALSA-2023:7765
ALSA-2023:7766
ALSA-2024:0121
ALSA-2025_16880
ALT-PU-2023-4689
ALT-PU-2023-4690
ALT-PU-2023-4711
ALT-PU-2023-4736
ALT-PU-2023-4785
ALT-PU-2023-5492
ALT-PU-2023-7055
AZL-27812
AZL-27814
AZL-37302
AZL-37344
AZL-52881
AZL-79008
BDU:2023-06242
BIT-GOLANG-2023-29409
CESA-2023_5721
CESA-2024_0121
CESA-2024_2988
CVE-2023-29409
GO-2023-1987
INFSA-2024_2988
OESA-2023-1530
OESA-2023-1531
OESA-2023-1532
OESA-2023-1533
OESA-2023-1591
OPENSUSE-SU-2023_3181-1
OPENSUSE-SU-2023_3263-1
OPENSUSE-SU-2023_3840-1
OPENSUSE-SU-2023_3841-1
OPENSUSE-SU-2023_3868-1
OPENSUSE-SU-2023_3885-1
OPENSUSE-SU-2023_3886-1
OPENSUSE-SU-2023_3888-1
OPENSUSE-SU-2024:13093-1
OPENSUSE-SU-2024:13094-1
RHSA-2023:5009
RHSA-2023:5721
RHSA-2023:5738
RHSA-2023:5805
RHSA-2023:5964
RHSA-2023:5965
RHSA-2023:5969
RHSA-2023:6298
RHSA-2023:6840
RHSA-2023:7762
RHSA-2023:7763
RHSA-2023:7764
RHSA-2023:7765
RHSA-2023:7766
RHSA-2023_5721
RHSA-2023_5738
RHSA-2023_7762
RHSA-2023_7763
RHSA-2023_7764
RHSA-2023_7765
RHSA-2023_7766
RHSA-2024:0121
RHSA-2024:0292
RHSA-2024:0293
RHSA-2024:2988
RHSA-2024_0121
RHSA-2024_2988
RLSA-2023:5738
SUSE-SU-2023:3181-1
SUSE-SU-2023:3263-1
SUSE-SU-2023:3474-1
SUSE-SU-2023:3840-1
SUSE-SU-2023:3841-1
SUSE-SU-2023:3861-1
SUSE-SU-2023:3867-1
SUSE-SU-2023:3868-1
SUSE-SU-2023:3875-1
SUSE-SU-2023:3885-1
SUSE-SU-2023:3886-1
SUSE-SU-2023:3888-1
SUSE-SU-2023_3181-1
SUSE-SU-2023_3263-1
SUSE-SU-2023_3840-1
SUSE-SU-2023_3888-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Red Hat
Rocky Linux
Suse
Crypto/Tls