PT-2024-4664 · Openssl+10 · Openssl+10

Matt Caswell

+2

·

Published

2024-05-10

·

Updated

2026-04-27

·

CVE-2024-4741

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: OpenSSL versions prior to 3.3 (FIPS modules in 3.3, 3.2, 3.1, and 3.0 are not affected)
Description: The issue is related to the SSL free buffers function in OpenSSL, which can cause memory to be accessed after it has been freed in certain situations. This can lead to corruption of valid data, crashes, or execution of arbitrary code. The function is used to free the internal OpenSSL buffer when processing an incoming record from the network. However, two scenarios have been identified where the buffer is freed even when still in use. A malicious attacker could attempt to engineer a situation where this occurs, although it is not aware of this issue being actively exploited.
Recommendations: As a temporary workaround, consider disabling the SSL free buffers function until a patch is available. Restrict access to the vulnerable SSL free buffers function to minimize the risk of exploitation. Avoid using the SSL free buffers function in applications that directly call it, as these are the only applications affected by this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:9333
ALSA-2024_9333
ALT-PU-2024-16921
ALT-PU-2024-16925
ALT-PU-2024-17181
ALT-PU-2025-1127
ALT-PU-2025-1184
AZL-42952
AZL-52910
AZL-52983
AZL-78564
BDU:2024-05176
CVE-2024-4741
DLA-3942-1
DLA-3942-2
ELSA-2024-9333
INFSA-2024_9333
JLSEC-2026-251
MGASA-2024-0200
MGASA-2024-0281
OESA-2024-1697
OESA-2024-1698
OESA-2024-1720
OESA-2024-1721
OESA-2025-1190
OESA-2025-1191
OESA-2025-1192
OESA-2025-1193
OESA-2025-1194
OPENSUSE-SU-2024:14219-1
OPENSUSE-SU-2024:14220-1
OPENSUSE-SU-2024_2020-1
OPENSUSE-SU-2024_2051-1
OPENSUSE-SU-2024_2059-1
OPENSUSE-SU-2024_2066-1
OPENSUSE-SU-2024_2088-1
OPENSUSE-SU-2024_2089-1
RHSA-2024:9333
RHSA-2024_9333
RLSA-2024:9333
RLSA-2024_9333
SUSE-SU-2024:2020-1
SUSE-SU-2024:2035-1
SUSE-SU-2024:2036-1
SUSE-SU-2024:2051-1
SUSE-SU-2024:2051-2
SUSE-SU-2024:2059-1
SUSE-SU-2024:2066-1
SUSE-SU-2024:2088-1
SUSE-SU-2024:2089-1
SUSE-SU-2024:2197-1
SUSE-SU-2024:2271-1
SUSE-SU-2024_2020-1
SUSE-SU-2024_2035-1
SUSE-SU-2024_2036-1
SUSE-SU-2024_2051-1
SUSE-SU-2024_2059-1
SUSE-SU-2024_2066-1
SUSE-SU-2024_2088-1
SUSE-SU-2024_2089-1
SUSE-SU-2025:03523-1
SUSE-SU-2025:03632-1
SUSE-SU-2025:20014-1
USN-6937-1
USN-7894-1
USN-7894-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Ibm Aix
Linuxmint
Openssl
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu