Improper Verification of Cryptographic Signature in AEADs aes-gcm - CVE-2023-42811

 

Improper Verification of Cryptographic Signature in AEADs aes-gcm - CVE-2023-42811

Published: October 3, 2023


Vulnerability identifier: #VU81449
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-42811
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to an error in AES GCM implementation of decrypt_in_place_detached. The decrypted ciphertext (i.e. the correct plaintext) is exposed even if tag verification fails. A local user can gain access to sensitive information.


Affected software

AEADs aes-gcm
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Fedora
Basesystem Module
openSUSE Leap
rage-encryption
rage-encryption-debuginfo
rage-encryption-zsh-completion
rage-encryption-bash-completion
rage-encryption-fish-completion
rust-aes-gcm
firecracker

How to mitigate CVE-2023-42811

Install updates from vendor's website.

AEADs aes-gcm - update to 0.10.3
rage-encryption - update to 0.9.2+0-150500.3.3.1
rage-encryption-debuginfo - update to 0.9.2+0-150500.3.3.1
rage-encryption-zsh-completion - update to 0.9.2+0-150500.3.3.1
rage-encryption-bash-completion - update to 0.9.2+0-150500.3.3.1
rage-encryption-fish-completion - update to 0.9.2+0-150500.3.3.1
rust-aes-gcm - addressed in versions 0.10.3-1.el9, 0.10.3-1.fc37, 0.10.3-1.fc38, 0.10.3-1.fc39, 0.10.3-1.fc40
firecracker - addressed in versions 1.4.1-3.fc37, 1.4.1-3.fc38, 1.4.1-3.fc39, 1.4.1-3.fc40

External References

Related Security Bulletins