Improper locking in OpenSSL - CVE-2022-3996
Published: December 13, 2022 / Updated: February 7, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack (DoS).
The vulnerability exists due to double-locking error if an X.509 certificate contains a malformed policy constraint and policy processing is enabled. A remote attacker can under certain circumstances perform a denial of service attack against the web server.
Successful exploitation of the vulnerability requires that policy processing being enabled on the server.
Affected software
Amazon Linux AMI
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
IBM AIX
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
VMware Tanzu Application Service for VMs
Isolation Segment
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Spectrum Protect Plus
Juniper Cloud Native Router
librdkafka
cflinuxfs3
Platform Automation Toolkit
Argo CD
IBM VIOS
Barracuda CloudGen WAN
openssl (Ubuntu package)
libssl-doc (Ubuntu package)
libssl1.0.0 (Ubuntu package)
openssl1.0 (Ubuntu package)
libssl1.1 (Ubuntu package)
libopenssl3
libopenssl-3-devel
libopenssl3-32bit-debuginfo
libopenssl3-32bit
libopenssl-3-devel-32bit
openssl-3-doc
openssl-3-debugsource
openssl-3-debuginfo
openssl-3
libopenssl3-debuginfo
libssl3 (Ubuntu package)
openssl
VMware Tanzu Operations Manager
Junos cRPD
How to mitigate CVE-2022-3996
librdkafka - update to 2.1.0
Argo CD - addressed in versions 2.3.13, 2.4.19
Barracuda CloudGen WAN - update to 8.3.1 1093
openssl (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22, 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
libssl-doc (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22, 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
libssl1.0.0 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.0.2n-1ubuntu5.12
cflinuxfs3 - update to 0.364.0
openssl1.0 (Ubuntu package) - update to 1.0.2n-1ubuntu5.12
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22
VMware Tanzu Operations Manager - addressed in versions 2.10.57, 3.0.8
libopenssl3 - update to 3.0.1-150400.4.14.1
libopenssl-3-devel - update to 3.0.1-150400.4.14.1
libopenssl3-32bit-debuginfo - update to 3.0.1-150400.4.14.1
libopenssl3-32bit - update to 3.0.1-150400.4.14.1
libopenssl-3-devel-32bit - update to 3.0.1-150400.4.14.1
openssl-3-doc - update to 3.0.1-150400.4.14.1
openssl-3-debugsource - update to 3.0.1-150400.4.14.1
openssl-3-debuginfo - update to 3.0.1-150400.4.14.1
openssl-3 - update to 3.0.1-150400.4.14.1
libopenssl3-debuginfo - update to 3.0.1-150400.4.14.1
libssl3 (Ubuntu package) - addressed in versions 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
openssl - update to 3.0.5-1
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
IBM Spectrum Protect Plus - update to 10.1.14
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
External References
Related Security Bulletins
- Denial of service in OpenSSL
- SUSE update for openssl-3
- Multiple vulnerabilities in argo-cd
- Multiple vulnerabilities in argo-cd
- Barracuda CloudGen WAN update for OpenSSL
- IBM AIX and VIOS update for OpenSSL
- Multiple vulnerabilities in librdkafka
- Cloud Foundry Foundation cflinuxfs3 update for OpenSSL
- Ubuntu update for openssl
- VMware Tanzu products update for OpenSSL
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Amazon Linux AMI update for openssl