Missing Encryption of Sensitive Data in OpenSSL - CVE-2022-2097

 

Missing Encryption of Sensitive Data in OpenSSL - CVE-2022-2097

Published: July 5, 2022


Vulnerability identifier: #VU64922
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2097
CWE-ID: CWE-311
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to an error in AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimized implementation. Under specific circumstances OpenSSL does not encrypt the entire message and can reveal sixteen bytes of data that was preexisting in the memory that wasn't written. A remote attacker can gain access to potentially sensitive information.



Affected software

OpenSSL
Amazon Linux AMI
Debian Linux
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Fedora
IBM AIX
SUSE Linux Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for Power, little endian
Oracle Solaris
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Slackware Linux
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Junos OS
Submariner
Gatekeeper Operator
Data Lakehouse
Sensor Proxy
IBM MQ Operator
IBM Spectrum Copy Data Management
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
OpenShift Logging
IBM Spectrum Control
IBM Sterling Connect:Direct for UNIX
Tenable Nessus
IBM Integration Bus
NetWorker
Autodesk Infraworks
Netcool Operations Insight
IBM SANnav Global View
IBM SANnav Management Portal
Red Hat OpenShift distributed tracing (RHOSDT)
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
EasyApache
App Connect Enterprise Certified Container
IBM Rational ClearCase
IBM Rational ClearQuest
IBM QRadar WinCollect Agent
IBM Spectrum Protect Plus
Red Hat OpenStack
PowerProtect Data Manager
IBM Robotic Process Automation
Self Node Remediation Operator
OpenShift sandboxed containers
Multicluster Engine for Kubernetes
OpenShift Service Mesh
Node Maintenance Operator
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
OpenShift API for Data Protection (OADP)
Argo CD
Migration Toolkit for Containers
Nessus Network Monitor
MySQL Enterprise Backup
Red Hat OpenShift Container Platform
IBM App Connect Professional
IBM VIOS
Red Hat Ceph Storage
MySQL Server
MySQL Enterprise Monitor
IBM InfoSphere Information Server
Nessus Agent
Cloud Pak for Security (CP4S)
MySQL Connectors
MySQL Workbench
IBM App Connect Enterprise
PeopleSoft Enterprise PeopleTools
IBM Cognos Analytics
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libopenssl1_1-debuginfo
libopenssl1_1
libopenssl-1_1-devel
libopenssl1_1-hmac
openssl-1_1
openssl-1_1-debuginfo
openssl-1_1-debugsource
libopenssl1_1-32bit
libopenssl1_1-32bit-debuginfo
libopenssl1_1-hmac-32bit
libopenssl-1_1-devel-32bit
libopenssl1_1-debuginfo-32bit
openssl-1_1-doc
openssl-debugsource
openssl-libs
openssl-debuginfo
openssl-devel
openssl-help
openssl
openssl11
openssl-perl
openssl (Red Hat package)
dev-libs/openssl
openssl1.1
libssl1.1 (Ubuntu package)
openssl (Debian package)
intel-sgx-ssl-devel
intel-sgx-ssl
sgx-ra-service
linux-sgx
libsgx-aesm-ecdsa-plugin
libsgx-ae-le
libsgx-dcap-ql
sgx-dcap-pccs
libsgx-launch-devel
sgx-aesm-service
libsgx-aesm-launch-plugin
libsgx-enclave-common-devel
sgxsdk
libsgx-quote-ex
libsgx-uae-service
libsgx-ra-network
libsgx-epid-devel
libsgx-enclave-common
libsgx-qe3-logic
libsgx-ae-qve
libsgx-dcap-default-qpl-devel
libsgx-ra-uefi-devel
libsgx-ae-pce
libsgx-pce-logic
libsgx-dcap-default-qpl
libsgx-ae-qe3
libsgx-aesm-pce-plugin
libsgx-epid
sgx-pck-id-retrieval-tool
libsgx-ra-uefi
libsgx-dcap-quote-verify-devel
libsgx-dcap-ql-devel
linux-sgx-debugsource
linux-sgx-debuginfo
libsgx-aesm-epid-plugin
libsgx-urts
libsgx-ae-epid
libsgx-quote-ex-devel
libsgx-dcap-quote-verify
libsgx-ra-network-devel
libsgx-launch
libsgx-aesm-quote-ex-plugin
openssl3
openssl-3-doc
openssl-3-debugsource
libopenssl-3-devel-32bit
openssl-3-debuginfo
libopenssl3
libopenssl3-debuginfo
libopenssl3-32bit
libopenssl3-32bit-debuginfo
libopenssl-3-devel
openssl-3
libssl3 (Ubuntu package)
nodejs-doc (Ubuntu package)
nodejs (Ubuntu package)
libnode72 (Ubuntu package)
libnode-dev (Ubuntu package)
nodejs12
nodejs12-docs
npm12
nodejs12-devel
nodejs12-debugsource
nodejs12-debuginfo
IBM Security Verify Access
cflinuxfs3
Db2 Rest
ObjectScale
Dell EMC Streaming Data Platform
Secured Component Verification (SCV)
PowerStore T
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Dell PowerProtect Cyber Recovery
SINEC INS
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC NetWorker vProxy
EMC ViPR SRM
SCALANCE XR528-6M
SCALANCE XM408-4C
SCALANCE XM408-8C
SCALANCE XM416-4C
SCALANCE XR524-8C
SCALANCE XR552-12M
SCALANCE XR526-8C
Dell EMC VxRail Appliance
Gaia

How to mitigate CVE-2022-2097

Install updates from vendor's website.

OpenSSL - addressed in versions 1.1.1q, 3.0.5
Submariner - update to 0.13.0
Gatekeeper Operator - update to 0.2
Self Node Remediation Operator - update to 0.4.1
OpenShift API for Data Protection (OADP) - addressed in versions 1.0.4, 1.1.0
OpenShift sandboxed containers - update to 1.3.1
Data Lakehouse - update to 1.1.0.0
Sensor Proxy - update to 1.0.7
IBM MQ Operator - addressed in versions 1.3.7, 2.0.2
Migration Toolkit for Containers - update to 1.7.4
Multicluster Engine for Kubernetes - addressed in versions 2.0.2, 2.1
OpenShift Service Mesh - update to 2.2.2
Argo CD - addressed in versions 2.2.12, 2.3.7, 2.4.8
IBM Spectrum Copy Data Management - update to 2.2.17
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.12, 2.4.6, 2.5.2, 2.6.0
Nessus Network Monitor - update to 6.1.0
Red Hat Advanced Cluster Security for Kubernetes - update to 3.72
Node Maintenance Operator - update to 4.11.1
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.1
OpenShift Logging - addressed in versions 5.3.11, 5.3.14, 5.4.5, 5.5.5
IBM Spectrum Control - update to 5.4.8
MySQL Server - addressed in versions 5.7.40, 8.0.31
Nessus Agent - update to 8.3.5
Tenable Nessus - update to 8.15.9
MySQL Connectors - update to 8.0.31
MySQL Workbench - update to 8.0.31
IBM Security Verify Access - update to 10.0.5.0
NetWorker - addressed in versions 19.11.0.6, 19.12.0.2
Junos OS - addressed in versions 22.1R3, 22.2R2, 22.3R1, 22.3R2
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
cflinuxfs3 - update to 0.309.0
SINEC INS - update to 1.0 SP2 Update 1
Db2 Rest - update to 1.0.0.304
libopenssl1_1-debuginfo - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.36.1, 1.1.1d-2.69.1, 1.1.1d-150200.11.51.1, 1.1.1l-150400.7.7.1
libopenssl1_1 - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.36.1, 1.1.1d-2.69.1, 1.1.1d-150200.11.51.1, 1.1.1l-150400.7.7.1
libopenssl-1_1-devel - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.36.1, 1.1.1d-2.69.1, 1.1.1d-150200.11.51.1, 1.1.1l-150400.7.7.1
libopenssl1_1-hmac - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.36.1, 1.1.1d-2.69.1, 1.1.1d-150200.11.51.1, 1.1.1l-150400.7.7.1
openssl-1_1 - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.36.1, 1.1.1d-2.69.1, 1.1.1d-150200.11.51.1, 1.1.1l-150400.7.7.1
openssl-1_1-debuginfo - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.36.1, 1.1.1d-2.69.1, 1.1.1d-150200.11.51.1, 1.1.1l-150400.7.7.1
openssl-1_1-debugsource - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.36.1, 1.1.1d-2.69.1, 1.1.1d-150200.11.51.1, 1.1.1l-150400.7.7.1
libopenssl1_1-32bit - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.36.1, 1.1.1d-2.69.1, 1.1.1d-150200.11.51.1, 1.1.1l-150400.7.7.1
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.36.1, 1.1.1d-150200.11.51.1, 1.1.1l-150400.7.7.1
libopenssl1_1-hmac-32bit - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.36.1, 1.1.1d-2.69.1, 1.1.1d-150200.11.51.1, 1.1.1l-150400.7.7.1
libopenssl-1_1-devel-32bit - addressed in versions 1.1.0i-150100.14.36.1, 1.1.1d-2.69.1, 1.1.1d-150200.11.51.1, 1.1.1l-150400.7.7.1
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.69.1
openssl-1_1-doc - addressed in versions 1.1.1d-150200.11.51.1, 1.1.1l-150400.7.7.1
openssl-debugsource - update to 1.1.1f-19
openssl-libs - update to 1.1.1f-19
openssl-debuginfo - update to 1.1.1f-19
openssl-devel - update to 1.1.1f-19
openssl-help - update to 1.1.1f-19
openssl - update to 1.1.1f-19
openssl11 - update to 1.1.1k-4.el7
openssl - update to 1.1.1k-7.0.1
openssl-devel - update to 1.1.1k-7.0.1
openssl-libs - update to 1.1.1k-7.0.1
openssl-perl - update to 1.1.1k-7.0.1
openssl (Red Hat package) - addressed in versions 1.1.1k-7.el8_6, 3.0.1-41.el9_0
dev-libs/openssl - update to 1.1.1q
openssl - addressed in versions 1.1.1q-1.fc35, 3.0.5-1.fc36, 3.0.5-1.fc37
openssl1.1 - update to 1.1.1q-1.fc36
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1l-1ubuntu1.6, 1.1.1f-1ubuntu2.16, 1.1.1-1ubuntu2.1~18.04.20
openssl (Debian package) - update to 1.1.1n-0+deb11u4
ObjectScale - update to 1.4.0
Netcool Operations Insight - update to 1.6.8
Dell EMC Streaming Data Platform - update to 1.7.0
Cloud Pak for Security (CP4S) - update to 1.10.12.0
Secured Component Verification (SCV) - update to 1.92.0
IBM SANnav Global View - addressed in versions 2.2.0.2, 2.2.1
IBM SANnav Management Portal - addressed in versions 2.2.0.2, 2.2.1
Red Hat OpenShift distributed tracing (RHOSDT) - update to 2.6.0
Isolation Segment - addressed in versions 2.7.47, 2.10.27, 2.11.16, 2.12.11
VMware Tanzu Application Service for VMs - addressed in versions 2.7.52, 2.10.34, 2.11.22, 2.12.16, 2.13.7
intel-sgx-ssl-devel - update to 2.10-4
intel-sgx-ssl - update to 2.10-4
sgx-ra-service - update to 2.11.100-11
linux-sgx - update to 2.11.100-11
libsgx-aesm-ecdsa-plugin - update to 2.11.100-11
libsgx-ae-le - update to 2.11.100-11
libsgx-dcap-ql - update to 2.11.100-11
sgx-dcap-pccs - update to 2.11.100-11
libsgx-launch-devel - update to 2.11.100-11
sgx-aesm-service - update to 2.11.100-11
libsgx-aesm-launch-plugin - update to 2.11.100-11
libsgx-enclave-common-devel - update to 2.11.100-11
sgxsdk - update to 2.11.100-11
libsgx-quote-ex - update to 2.11.100-11
libsgx-uae-service - update to 2.11.100-11
libsgx-ra-network - update to 2.11.100-11
libsgx-epid-devel - update to 2.11.100-11
libsgx-enclave-common - update to 2.11.100-11
libsgx-qe3-logic - update to 2.11.100-11
libsgx-ae-qve - update to 2.11.100-11
libsgx-dcap-default-qpl-devel - update to 2.11.100-11
libsgx-ra-uefi-devel - update to 2.11.100-11
libsgx-ae-pce - update to 2.11.100-11
libsgx-pce-logic - update to 2.11.100-11
libsgx-dcap-default-qpl - update to 2.11.100-11
libsgx-ae-qe3 - update to 2.11.100-11
libsgx-aesm-pce-plugin - update to 2.11.100-11
libsgx-epid - update to 2.11.100-11
sgx-pck-id-retrieval-tool - update to 2.11.100-11
libsgx-ra-uefi - update to 2.11.100-11
libsgx-dcap-quote-verify-devel - update to 2.11.100-11
libsgx-dcap-ql-devel - update to 2.11.100-11
linux-sgx-debugsource - update to 2.11.100-11
linux-sgx-debuginfo - update to 2.11.100-11
libsgx-aesm-epid-plugin - update to 2.11.100-11
libsgx-urts - update to 2.11.100-11
libsgx-ae-epid - update to 2.11.100-11
libsgx-quote-ex-devel - update to 2.11.100-11
libsgx-dcap-quote-verify - update to 2.11.100-11
libsgx-ra-network-devel - update to 2.11.100-11
libsgx-launch - update to 2.11.100-11
libsgx-aesm-quote-ex-plugin - update to 2.11.100-11
openssl3 - update to 3.0.1-41.el8.1
openssl-3-doc - update to 3.0.1-150400.4.7.1
openssl-3-debugsource - update to 3.0.1-150400.4.7.1
libopenssl-3-devel-32bit - update to 3.0.1-150400.4.7.1
openssl-3-debuginfo - update to 3.0.1-150400.4.7.1
libopenssl3 - update to 3.0.1-150400.4.7.1
libopenssl3-debuginfo - update to 3.0.1-150400.4.7.1
libopenssl3-32bit - update to 3.0.1-150400.4.7.1
libopenssl3-32bit-debuginfo - update to 3.0.1-150400.4.7.1
libopenssl-3-devel - update to 3.0.1-150400.4.7.1
openssl-3 - update to 3.0.1-150400.4.7.1
libssl3 (Ubuntu package) - update to 3.0.2-0ubuntu1.6
openssl - addressed in versions 3.0.5-1, 3.0.8-1
PowerStore T - update to 3.5.0.1-2083289
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Cloud Pak for Watson AIOps - update to 4.2.1
Dell EMC NetWorker vProxy - update to 4.3.0-34
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.2
EMC ViPR SRM - update to 4.8.0.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.1
DB2 on Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
OpenShift Virtualization - addressed in versions 4.11.0, 4.11.1, 4.12.0
EasyApache - update to 4 2022-7-6
App Connect Enterprise Certified Container - addressed in versions 5.0.1, 5.2.0
SCALANCE XR528-6M - update to 6.6.1
SCALANCE XM408-4C - update to 6.6.1
SCALANCE XM408-8C - update to 6.6.1
SCALANCE XM416-4C - update to 6.6.1
SCALANCE XR524-8C - update to 6.6.1
SCALANCE XR552-12M - update to 6.6.1
SCALANCE XR526-8C - update to 6.6.1
Dell EMC VxRail Appliance - update to 8.0.000
IBM Rational ClearCase - addressed in versions 9.0.2.7, 9.1.0.4, 10.0.0.1
IBM Rational ClearQuest - addressed in versions 9.0.2.7, 9.1.0.4
IBM QRadar WinCollect Agent - update to 10.1.1
IBM Spectrum Protect Plus - update to 10.1.12
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
IBM InfoSphere Information Server - addressed in versions 11.7.1.0, 11.7.1.4
nodejs-doc (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
nodejs (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
libnode72 (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
libnode-dev (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
nodejs12 - update to 12.22.12-1.51.1
nodejs12-docs - update to 12.22.12-1.51.1
npm12 - update to 12.22.12-1.51.1
nodejs12-devel - update to 12.22.12-1.51.1
nodejs12-debugsource - update to 12.22.12-1.51.1
nodejs12-debuginfo - update to 12.22.12-1.51.1
Red Hat OpenStack - update to 16.2.z
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
PowerProtect Data Manager - update to 19.19.0-15
IBM Robotic Process Automation - update to 21.0.5
Gaia - update to R81.10 Take 95

External References

Related Security Bulletins