PT-2024-3762 · Openssl+10 · Openssl+10

Manish Patidar

+1

·

Published

2024-04-08

·

Updated

2026-04-27

·

CVE-2024-2511

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 3.3.0
Description The issue is related to unbounded memory growth when processing TLSv1.3 sessions due to the use of the non-default SSL OP NO TICKET option. This can lead to a Denial of Service. The problem occurs when the session cache gets into an incorrect state and fails to flush properly as it fills. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. This issue only affects TLS servers supporting TLSv1.3 and does not affect TLS clients. The FIPS modules in 3.2, 3.1, and 3.0 are not affected by this issue, nor is OpenSSL 1.0.2.
Recommendations To resolve the issue, update to OpenSSL version 3.3.0 or later. As a temporary workaround, consider disabling the use of the SSL OP NO TICKET option in TLSv1.3 server configurations until a patch is available. Restrict access to TLSv1.3 sessions to minimize the risk of exploitation. Avoid using the SSL OP NO TICKET option in TLSv1.3 server configurations until the issue is resolved.

Exploit

Fix

DoS

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:9333
ALT-PU-2024-16921
ALT-PU-2024-16925
ALT-PU-2024-17181
ALT-PU-2025-1127
ALT-PU-2025-1184
AZL-39794
AZL-39797
AZL-40192
AZL-42700
AZL-42765
AZL-42949
AZL-47649
AZL-78543
BDU:2024-04109
CVE-2024-2511
DLA-3942-1
DLA-3942-2
INFSA-2024_9333
JLSEC-2026-249
MGASA-2024-0129
MGASA-2024-0281
OESA-2024-1513
OESA-2024-1531
OPENSUSE-SU-2024:13937-1
OPENSUSE-SU-2024:13942-1
OPENSUSE-SU-2024_1634-1
OPENSUSE-SU-2024_1808-1
OPENSUSE-SU-2024_1947-1
OPENSUSE-SU-2024_1949-1
RHSA-2024:9333
RHSA-2024_9333
RLSA-2024:9333
SUSE-SU-2024:1633-1
SUSE-SU-2024:1634-1
SUSE-SU-2024:1808-1
SUSE-SU-2024:1947-1
SUSE-SU-2024:1949-1
SUSE-SU-2024:2953-1
SUSE-SU-2024_1633-1
SUSE-SU-2024_1634-1
SUSE-SU-2024_1808-1
SUSE-SU-2024_1947-1
SUSE-SU-2024_1949-1
SUSE-SU-2024_2953-1
SUSE-SU-2025:20014-1
USN-6937-1
USN-7894-1
USN-7894-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Ibm Aix
Linuxmint
Openssl
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu