PT-2026-102653 · Openssl+2 · Openssl+2
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSSL (affected versions not specified)
Description
A TLS server may experience an out-of-bounds read and a fixed-value out-of-bounds write on the server heap when calling the
SSL set SSL CTX() function to switch a connection to a different SSL CTX during a handshake. This occurs if the replacement context recognizes more provider signature algorithms than the original context used to create the connection, as the internal array of per-slot certificate validity flags is not refreshed. A remote peer can trigger this by offering multiple signature algorithms, potentially corrupting heap metadata and causing a Denial of Service. This issue specifically affects provider signature algorithms usable from TLS 1.3.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, avoid calling the
SSL set SSL CTX() function during the handshake process.Exploit
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Openssl
Ubuntu