State Issues in OpenSSL - CVE-2023-6129
Published: January 9, 2024 / Updated: April 8, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error in POLY1305 MAC (message authentication code) implementation on PowerPC CPU based platforms if the CPU provides vector instructions. A remote attacker can perform a denial of service (DoS) attack.
Affected software
IBM Business Automation Workflow
IBM Cloud Transformation Advisor
IBM Rational Build Forge
Oracle HTTP Server
IBM Automation Decision Services
Service Interconnect
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Custom Metrics Autoscaler Operator for Red Hat OpenShift
IBM MaaS360 Mobile Enterprise Gateway
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Migration Toolkit for Applications
IBM Rational ClearCase
IBM Rational ClearQuest
Rational Application Developer
IBM QRadar WinCollect Agent
IBM Workload Scheduler
Red Hat OpenStack
IBM Cloud Pak for Business Automation
IBM Observability with Instana
IBM AIX
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Linux Enterprise Micro
IBM i
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Brocade Fabric OS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
IBM VIOS
Rational Developer for i RPG and COBOL + Modernization Tools, Java Edition
Telemetry Dashboard
Guardium Data Security Center (GDSC)
Liquidware
Citrix Workspace App
Webex App VDI
IBM Cloud Pak for Watson AIOps
Storage Resource Manager
Maximo Application Suite - Edge Data Collector
IBM Virtualization Engine TS7700 3948-VED
JD Edwards World Security
Dell EMC NetWorker vProxy
Voice Gateway
Cisco Webex Meetings
Intel In-Band Manageability
IBM Qradar SIEM
MySQL Enterprise Backup
JD Edwards EnterpriseOne Tools
VMware Horizon Client
Red Hat OpenShift Container Platform
MySQL Server
MySQL Enterprise Monitor
IBM InfoSphere Information Server
MySQL Connectors
MySQL Workbench
IBM App Connect Enterprise
Cisco Jabber
Oracle Banking Branch
Oracle Banking Liquidity Management
IBM Integrated Analytics System
libssl1.1 (Ubuntu package)
libssl3 (Ubuntu package)
openssl-fips-provider (Red Hat package)
openssl (Red Hat package)
openssl-3-debuginfo
libopenssl-3-devel
libopenssl3-debuginfo
openssl-3-debugsource
openssl-3
libopenssl3
libopenssl-3-devel-32bit
libopenssl3-32bit
libopenssl3-32bit-debuginfo
openssl-3-doc
libopenssl3-64bit-debuginfo
libopenssl-3-devel-64bit
libopenssl3-64bit
openssl
openssl-devel
openssl-libs
openssl-perl
openssl-doc
mysql-server
mysql-debuginfo
mysql-devel
mysql
mysql-config
mysql-help
mysql-errmsg
mysql-libs
mysql-test
mysql-common
mysql-debugsource
edk2 (Red Hat package)
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
OpenShift Service Mesh
OpenShift Virtualization
OpenShift Container Platform for Windows Containers
IBM MaaS360 VPN Module
Dell EMC Storage Monitoring and Reporting (SMR)
Virtualization Engine TS7700 3957-VED
IBM Security Guardium
How to mitigate CVE-2023-6129
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Voice Gateway - update to 1.0.8.12
IBM Cloud Transformation Advisor - update to 3.10.2
Intel In-Band Manageability - update to 4.2.1
Guardium Data Security Center (GDSC) - update to 3.6.1
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Qradar SIEM - update to 7.5.0 Update Pack 8
IBM Rational Build Forge - update to 8.0.0.26
MySQL Workbench - update to 8.0.38
Brocade Fabric OS - addressed in versions 9.2.0c, 9.2.1a1, 9.2.2
JD Edwards EnterpriseOne Tools - update to 9.2.9.0
IBM App Connect Enterprise - addressed in versions 11.0.0.25, 12.0.11.2
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
IBM Automation Decision Services - update to 24.0.0.0.4
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
IBM Integrated Analytics System - update to 1.0.30.0
libssl1.1 (Ubuntu package) - update to 1.1.1f-1ubuntu2.21
OpenShift API for Data Protection (OADP) - update to 1.3.2
Service Interconnect - update to 1.5.4
Network Observability plugin for the Openshift Console - update to 1.6.0
Ansible Automation Platform - update to 2.4
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.2
Red Hat Advanced Cluster Management for Kubernetes - update to 2.10.5
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-394
libssl3 (Ubuntu package) - addressed in versions 3.0.2-0ubuntu1.14, 3.0.10-1ubuntu2.2
openssl-fips-provider (Red Hat package) - update to 3.0.7-2.el9
openssl (Red Hat package) - update to 3.0.7-27.el9
openssl-3-debuginfo - addressed in versions 3.0.8-150400.4.49.1, 3.0.8-150500.5.24.1
libopenssl-3-devel - addressed in versions 3.0.8-150400.4.49.1, 3.0.8-150500.5.24.1
libopenssl3-debuginfo - addressed in versions 3.0.8-150400.4.49.1, 3.0.8-150500.5.24.1
openssl-3-debugsource - addressed in versions 3.0.8-150400.4.49.1, 3.0.8-150500.5.24.1
openssl-3 - addressed in versions 3.0.8-150400.4.49.1, 3.0.8-150500.5.24.1
libopenssl3 - addressed in versions 3.0.8-150400.4.49.1, 3.0.8-150500.5.24.1
libopenssl-3-devel-32bit - addressed in versions 3.0.8-150400.4.49.1, 3.0.8-150500.5.24.1
libopenssl3-32bit - addressed in versions 3.0.8-150400.4.49.1, 3.0.8-150500.5.24.1
libopenssl3-32bit-debuginfo - addressed in versions 3.0.8-150400.4.49.1, 3.0.8-150500.5.24.1
openssl-3-doc - addressed in versions 3.0.8-150400.4.49.1, 3.0.8-150500.5.24.1
libopenssl3-64bit-debuginfo - addressed in versions 3.0.8-150400.4.49.1, 3.0.8-150500.5.24.1
libopenssl-3-devel-64bit - addressed in versions 3.0.8-150400.4.49.1, 3.0.8-150500.5.24.1
libopenssl3-64bit - addressed in versions 3.0.8-150400.4.49.1, 3.0.8-150500.5.24.1
openssl - update to 3.0.12-3
openssl-devel - update to 3.0.12-3
openssl-libs - update to 3.0.12-3
openssl-perl - update to 3.0.12-3
openssl-doc - update to 3.0.12-3
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.800
IBM MaaS360 VPN Module - update to 3.000.800
Red Hat OpenShift Dev Spaces - update to 3.16.0
IBM Cloud Pak for Watson AIOps - update to 4.7.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.7
OpenShift Virtualization - update to 4.14.6
Red Hat OpenShift Container Platform - update to 4.17.0
Storage Resource Manager - update to 5.0.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Red Hat Migration Toolkit for Applications - addressed in versions 6.2.3, 7.0.3
mysql-server - addressed in versions 8.0.37-1, 8.0.37-2, 8.0.38-1
mysql-debuginfo - addressed in versions 8.0.37-1, 8.0.37-2, 8.0.38-1
mysql-devel - addressed in versions 8.0.37-1, 8.0.37-2, 8.0.38-1
mysql - addressed in versions 8.0.37-1, 8.0.37-2, 8.0.38-1
mysql-config - addressed in versions 8.0.37-1, 8.0.37-2, 8.0.38-1
mysql-help - addressed in versions 8.0.37-1, 8.0.37-2, 8.0.38-1
mysql-errmsg - addressed in versions 8.0.37-1, 8.0.37-2, 8.0.38-1
mysql-libs - addressed in versions 8.0.37-1, 8.0.37-2, 8.0.38-1
mysql-test - addressed in versions 8.0.37-1, 8.0.37-2, 8.0.38-1
mysql-common - addressed in versions 8.0.37-1, 8.0.37-2, 8.0.38-1
mysql-debugsource - addressed in versions 8.0.37-1, 8.0.37-2, 8.0.38-1
OpenShift Container Platform for Windows Containers - addressed in versions 8.1.3, 10.15.3
Maximo Application Suite - Edge Data Collector - update to 8.11.7
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.53.1.21 VTD_EXEC.279, 8.54.0.68 VTD_EXEC.279, 8.54.1.27 VTD_EXEC.279
Virtualization Engine TS7700 3957-VED - addressed in versions 8.53.1.21 VTD_EXEC.279, 8.54.0.68 VTD_EXEC.279, 8.54.1.27 VTD_EXEC.279
IBM Rational ClearCase - addressed in versions 9.1.0.7, 10.0.1.2, 11.0.0.1
IBM Rational ClearQuest - update to 9.1.0.7
Rational Application Developer - update to 9.7.0.6
IBM QRadar WinCollect Agent - update to 10.1.9
IBM Workload Scheduler - update to 10.2.2
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
IBM Security Guardium - update to 12.0 p6009
Red Hat OpenStack - update to 17.1
Dell EMC NetWorker vProxy - addressed in versions 19.11.0.5, 19.12.0.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.33, 23.0.2.5
IBM Observability with Instana - update to 281
edk2 (Red Hat package) - update to 20240524-6.el9_5
External References
Related Security Bulletins
- Denial of service in OpenSSL
- SUSE update for openssl-3
- Multiple vulnerabilities in IBM AIX and IBM VIOS
- Ubuntu update for openssl
- SUSE update for openssl-3
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- intel-inb-manageability update for OpenSSL
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Rational Build Forge
- State Issues in IBM System Storage Virtualization Engine TS7700
- Multiple vulnerabilities in MySQL Server
- State Issues in MySQL Enterprise Monitor
- Multiple vulnerabilities in MySQL Enterprise Backup
- Multiple vulnerabilities in MySQL Connectors
- Red Hat Enterprise Linux 9 update for openssl and openssl-fips-provider
- openEuler 22.03 LTS SP2 update for mysql
- openEuler 22.03 LTS SP3 update for mysql
- openEuler 22.03 LTS update for mysql
- openEuler 22.03 LTS SP1 update for mysql
- Multiple vulnerabilities in Rational Application Developer
- Multiple vulnerabilities in IBM Edge Data Collector
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender Mobile Enterprise Gateway (MEG) and VPN Module
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM RDi RPG and COBOL + Modernization Tools, Java Edition
- Multiple vulnerabilities in Network Observability plugin for the Openshift Console 1.6
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in Custom Metrics Autoscaler Operator for Red Hat OpenShift 2.12
- Multiple vulnerabilities in OpenShift Virtualization 4.14
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in OpenShift Service Mesh 2.4
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in Red Hat OpenStack 17.1 packages
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications 6.2
- Multiple vulnerabilities in Service Interconnect 1.5
- openEuler 24.03 LTS update for mysql
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in Oracle HTTP Server
- Multiple vulnerabilities in Oracle Banking Liquidity Management
- Multiple vulnerabilities in Oracle Banking Branch
- State Issues in JD Edwards World Security
- Multiple vulnerabilities in MySQL Workbench
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in IBM Rational ClearCase
- Multiple vulnerabilities in OpenShift Container Platform for Windows Containers 10.15
- Multiple vulnerabilities in IBM Rational ClearQuest
- State Issues in IBM Workload Scheduler
- Multiple vulnerabilities in IBM Security Guardium
- openEuler 20.03 LTS SP4 update for mysql
- Multiple vulnerabilities in OpenShift Container Platform for Windows Containers 8.1
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- IBM Integrated Analytics System update for OpenSSL
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Red Hat Enterprise Linux 9 update for edk2
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Brocade Fabric OS
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Multiple vulnerabilities in Guardium Data Security Center
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Anolis OS update for openssl
- Dell EMC NetWorker vProxy update for third-party components
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM i
- Multiple vulnerabilities in IBM Automation Decision Services
- Multiple vulnerabilities in IBM Automation Decision Services
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications 7.0