PT-2024-7386 · Openssl+6 · Openssl+6

Dr. Christopher Kunz

+2

·

Published

2024-05-10

·

Updated

2026-04-27

·

CVE-2024-9143

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: OpenSSL versions prior to 3.3.3
Description: The issue arises from the use of low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial, leading to out-of-bounds memory reads or writes. This can cause an application crash or potentially allow for remote code execution. However, the likelihood of a vulnerable application is low, as most protocols involving Elliptic Curve Cryptography either support only "named curves" or specify an X9.62 encoding of binary (GF(2^m)) curves that cannot represent problematic input values. The affected APIs include EC GROUP new curve GF2m(), EC GROUP new from params(), and various supporting BN GF2m *() functions.
Recommendations: For versions prior to 3.3.3, update to version 3.3.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the vulnerable EC GROUP new curve GF2m() and EC GROUP new from params() functions, as well as the supporting BN GF2m *() functions, until a patch is available. Avoid using "exotic" explicit binary (GF(2^m)) curve parameters that can represent invalid field polynomials with a zero constant term.

Fix

RCE

Buffer Overflow

Integer Overflow

Out of bounds Read

Memory Corruption

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2024-16921
ALT-PU-2024-16925
ALT-PU-2024-17181
ALT-PU-2025-1127
ALT-PU-2025-1184
AZL-78531
BDU:2024-05176
BDU:2024-08755
BDU:2025-11907
CVE-2024-9143
DLA-3942-1
DLA-3942-2
JLSEC-2026-254
MGASA-2024-0354
MGASA-2024-0355
MGASA-2025-0210
OESA-2024-2384
OESA-2024-2385
OESA-2024-2386
OESA-2024-2387
OESA-2024-2480
OESA-2025-1352
OPENSUSE-SU-2024:14416-1
USN-7264-1
USN-7278-1
USN-7894-1
USN-7894-2

Affected Products

Alt Linux
Astra Linux
Ibm Aix
Linuxmint
Openssl
Red Os
Ubuntu