PT-2023-7560 · Openssl+11 · Openssl+11

David Benjamin

+1

·

Published

2023-10-24

·

Updated

2026-04-29

·

CVE-2023-5678

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.1.1w
Description The issue is related to the generation and checking of excessively long X9.42 DH keys or parameters, which may cause long delays in applications using the affected functions. This can lead to a Denial of Service attack if the key or parameters are obtained from an untrusted source. The DH generate key() and DH check pub key() functions are vulnerable to excessively large P and Q parameters. Other affected functions include DH check pub key ex(), EVP PKEY public check(), and EVP PKEY generate(). The OpenSSL pkey command line application and the OpenSSL genpkey command line application are also vulnerable when using the "-pubcheck" option.
Recommendations To resolve the issue, update OpenSSL to version 1.1.1w or later. As a temporary workaround, consider disabling the DH generate key() and DH check pub key() functions until a patch is available. Restrict access to the vulnerable DH check pub key ex(), EVP PKEY public check(), and EVP PKEY generate() functions to minimize the risk of exploitation. Avoid using the pkey command line application with the "-pubcheck" option and the genpkey command line application until the issue is resolved.

Fix

DoS

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

ALSA-2023:7877
ALSA-2024:2447
ALT-PU-2024-16921
ALT-PU-2024-16925
ALT-PU-2024-17181
ALT-PU-2024-1746
ALT-PU-2025-1127
ALT-PU-2025-1184
AZL-31872
AZL-31880
AZL-34666
AZL-35084
AZL-37740
AZL-39659
AZL-42685
AZL-42736
AZL-78555
BDU:2023-08615
CESA-2023_7877
CVE-2023-5678
DLA-3942-1
DLA-3942-2
INFSA-2024_2447
JLSEC-2026-244
MGASA-2024-0020
MGASA-2024-0036
MGASA-2024-0281
OESA-2023-1821
OESA-2025-1747
OESA-2025-1802
OPENSUSE-SU-2023_4518-1
OPENSUSE-SU-2023_4522-1
OPENSUSE-SU-2023_4524-1
OPENSUSE-SU-2023_4649-1
OPENSUSE-SU-2024:13428-1
OPENSUSE-SU-2024:13437-1
OPENSUSE-SU-2024:13438-1
RHSA-2023:7877
RHSA-2023_7877
RHSA-2024:0154
RHSA-2024:0208
RHSA-2024:1316
RHSA-2024:1318
RHSA-2024:2447
RHSA-2024_2447
ROSA-SA-2025-2617
SUSE-SU-2023:4488-1
SUSE-SU-2023:4489-1
SUSE-SU-2023:4518-1
SUSE-SU-2023:4519-1
SUSE-SU-2023:4520-1
SUSE-SU-2023:4521-1
SUSE-SU-2023:4522-1
SUSE-SU-2023:4523-1
SUSE-SU-2023:4524-1
SUSE-SU-2023:4593-1
SUSE-SU-2023:4635-1
SUSE-SU-2023:4649-1
SUSE-SU-2023:4918-1
SUSE-SU-2023:4919-1
SUSE-SU-2023_4488-1
SUSE-SU-2023_4489-1
SUSE-SU-2023_4518-1
SUSE-SU-2023_4519-1
SUSE-SU-2023_4520-1
SUSE-SU-2023_4521-1
SUSE-SU-2023_4522-1
SUSE-SU-2023_4523-1
SUSE-SU-2023_4524-1
SUSE-SU-2023_4593-1
SUSE-SU-2023_4635-1
SUSE-SU-2023_4649-1
USN-6622-1
USN-6632-1
USN-6709-1
USN-7894-1
USN-7894-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Ibm Aix
Linuxmint
Openssl
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu