PT-2024-2726 · Mysql Server+9 · Mysql Server+9

Rohan Mclure

+1

·

Published

2024-01-09

·

Updated

2026-04-27

·

CVE-2023-6129

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to the fixed version MySQL Server versions 8.0.36 and earlier, 8.3.0 and earlier
Description The POLY1305 MAC implementation in OpenSSL contains a bug that might corrupt the internal state of applications running on PowerPC CPU based platforms if the CPU provides vector instructions. If an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various application dependent consequences. The vulnerable code is used only on newer PowerPC processors supporting the PowerISA 2.07 instructions. The consequences of this kind of internal application state corruption can be various, from no consequences to the worst consequences, where the attacker could get complete control of the application process. However, unless the compiler uses the vector registers for storing pointers, the most likely consequence, if any, would be an incorrect result of some application dependent calculations or a crash leading to a denial of service.
Recommendations For OpenSSL versions prior to the fixed version: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For MySQL Server versions 8.0.36 and earlier, 8.3.0 and earlier: Update to a version that is not affected by this issue. As a temporary workaround, consider disabling the use of the POLY1305 MAC algorithm until a patch is available. Restrict access to the vulnerable code to minimize the risk of exploitation. Avoid using the CHACHA20-POLY1305 AEAD cipher with TLS protocol versions 1.2 and 1.3 until the issue is resolved.

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

ALSA-2024:2447
ALSA-2024:9088
ALT-PU-2024-1746
AZL-35044
AZL-35085
AZL-42697
AZL-42754
AZL-47643
AZL-78582
BDU:2024-02846
CVE-2023-6129
INFSA-2024_2447
INFSA-2024_9088
JLSEC-2026-245
MGASA-2024-0020
MGASA-2024-0036
MGASA-2024-0281
OESA-2024-1558
OESA-2024-1559
OESA-2024-1560
OESA-2024-1561
OESA-2024-1744
OESA-2024-2071
OPENSUSE-SU-2024:13633-1
OPENSUSE-SU-2024_0172-1
OPENSUSE-SU-2024_0518-1
RHSA-2024:2447
RHSA-2024:9088
RHSA-2024_2447
RHSA-2024_9088
RLSA-2024:9088
SUSE-SU-2024:0172-1
SUSE-SU-2024:0518-1
SUSE-SU-2024_0172-1
SUSE-SU-2024_0518-1
USN-6622-1

Affected Products

Alt Linux
Almalinux
Ibm Aix
Linuxmint
Mysql Server
Openssl
Red Hat
Rocky Linux
Suse
Ubuntu