Out-of-bounds read in OpenSSL - CVE-2023-1255

 

Out-of-bounds read in OpenSSL - CVE-2023-1255

Published: April 20, 2023 / Updated: October 11, 2023


Vulnerability identifier: #VU75388
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-1255
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the AES-XTS cipher decryption implementation for 64 bit ARM platform. An attacker with ability to control the size and location of the ciphertext buffer can trigger an out-of-bounds read and crash the application.

Affected software

OpenSSL
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Basesystem Module
openSUSE Leap
Ubuntu
Junos OS Evolved
Isolation Segment
VMware Tanzu Application Service for VMs
cert-manager Operator for Red Hat OpenShift
IBM QRadar WinCollect Agent
Sensor Proxy
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
Storage Ceph
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Dell Data Protection Central
OpenShift sandboxed containers
OpenShift Data Foundation (formerly OpenShift Container Storage)
VMware Tanzu Operations Manager
Red Hat OpenShift Container Platform
VMware Horizon Client
SecurityCenter
Nessus Agent
Cisco Jabber
Cisco Webex Meetings
libssl1.0.0 (Ubuntu package)
libssl1.1 (Ubuntu package)
libssl3 (Ubuntu package)
openssl (Red Hat package)
openssl
libopenssl3-debuginfo
libopenssl-3-devel
libopenssl3-32bit
libopenssl3
openssl-3-debuginfo
openssl-3
libopenssl3-32bit-debuginfo
libopenssl-3-devel-32bit
openssl-3-doc
openssl-3-debugsource
libopenssl3-64bit
libopenssl-3-devel-64bit
libopenssl3-64bit-debuginfo
Network Observability plugin for the Openshift Console

How to mitigate CVE-2023-1255

Install update from vendor's website.

OpenSSL - addressed in versions 3.0.9, 3.1.1
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
OpenShift sandboxed containers - update to 1.4.1
cert-manager Operator for Red Hat OpenShift - update to 1.10.3
Red Hat OpenShift Container Platform - addressed in versions 4.12.23, 4.13.5, 4.13.6
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.1
SecurityCenter - update to 6.2.0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Nessus Agent - update to 10.4.1
IBM QRadar WinCollect Agent - update to 10.1.8
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Junos OS Evolved - addressed in versions 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.3R3-S2-EVO, 22.4R3-S1-EVO, 23.2R2-EVO, 23.4R1-EVO
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libssl1.0.0 (Ubuntu package) - update to 1.0.2n-1ubuntu5.13
Sensor Proxy - update to 1.0.8
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.19, 1.1.1-1ubuntu2.1~18.04.23
Network Observability plugin for the Openshift Console - update to 1.3.0
libssl3 (Ubuntu package) - addressed in versions 3.0.2-0ubuntu1.10, 3.0.5-2ubuntu2.3, 3.0.8-1ubuntu1.2
openssl (Red Hat package) - update to 3.0.7-16.el9_2
openssl - update to 3.0.8-1
libopenssl3-debuginfo - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
libopenssl-3-devel - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
libopenssl3-32bit - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
libopenssl3 - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
openssl-3-debuginfo - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
openssl-3 - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
libopenssl3-32bit-debuginfo - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
libopenssl-3-devel-32bit - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
openssl-3-doc - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
openssl-3-debugsource - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
libopenssl3-64bit - update to 3.0.8-150500.5.3.1
libopenssl-3-devel-64bit - update to 3.0.8-150500.5.3.1
libopenssl3-64bit-debuginfo - update to 3.0.8-150500.5.3.1
VMware Tanzu Operations Manager - update to 3.0.11
IBM Cloud Pak for Watson AIOps - update to 4.1.2
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.4
Storage Ceph - update to 6.1z1
App Connect Enterprise Certified Container - update to 7.0.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.22.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.22.0
Dell Data Protection Central - update to 19.11.0-2

External References

Related Security Bulletins