PT-2023-6818 · Openssl+9 · Openssl+9

Tony Battersby

·

Published

2023-10-24

·

Updated

2026-04-27

·

CVE-2023-5363

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions 3.0 and 3.1
Description A bug has been identified in the processing of key and initialisation vector (IV) lengths, potentially leading to truncation or overruns during the initialisation of some symmetric ciphers. This issue can result in non-uniqueness, leading to loss of confidentiality for some cipher modes. The affected ciphers and modes include RC2, RC4, RC5, CCM, GCM, and OCB. Truncation of the IV in CCM, GCM, and OCB modes can lead to loss of confidentiality. For example, when following NIST's SP 800-38D guidance for constructing a deterministic IV for AES in GCM mode, truncation of the counter portion could lead to IV reuse. The EVP EncryptInit ex2(), EVP DecryptInit ex2(), and EVP CipherInit ex2() functions are impacted, and alterations to the key length via the keylen parameter or the IV length via the ivlen parameter within the OSSL PARAM array may not take effect as intended.
Recommendations For OpenSSL versions 3.0 and 3.1, update to a fixed version to resolve the issue. As a temporary workaround, consider restricting the use of the vulnerable EVP EncryptInit ex2(), EVP DecryptInit ex2(), and EVP CipherInit ex2() functions until a patch is available. Avoid using the keylen and ivlen parameters within the OSSL PARAM array to minimize the risk of exploitation.

Fix

DoS

Weakness Enumeration

Related Identifiers

ALSA-2024:0310
ALT-PU-2023-6611
AZL-42712
AZL-42751
AZL-78558
BDU:2023-07691
CVE-2023-5363
DSA-5532-1
JLSEC-2026-243
MGASA-2023-0313
MGASA-2023-0317
OESA-2025-1191
OESA-2025-1192
OPENSUSE-SU-2023_4189-1
OPENSUSE-SU-2023_4190-1
OPENSUSE-SU-2024:13372-1
RHSA-2024:0310
RHSA-2024:0500
RHSA-2024_0310
SUSE-SU-2023:4189-1
SUSE-SU-2023:4190-1
USN-6450-1

Affected Products

Alt Linux
Almalinux
Ibm Aix
Linuxmint
Mysql Server
Openssl
Red Hat
Red Os
Suse
Ubuntu