Type Confusion in OpenSSL - CVE-2024-6119

 

Type Confusion in OpenSSL - CVE-2024-6119

Published: September 3, 2024 / Updated: September 11, 2024


Vulnerability identifier: #VU96744
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-6119
CWE-ID: CWE-843
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a type confusion error when performing certificate name checks. A remote attacker can supply a specially crafted X.509 certificate to the server, trigger a type confusion error and perform a denial of service (DoS) attack.


Affected software

OpenSSL
Debian Linux
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
BIG-IP Next CNF
BIG-IP Next SPK
IBM i
IBM AIX
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
FreeBSD
Certifications Module
Ubuntu
Anolis OS
openEuler
Fedora
IBM Concert Software
z/Transaction Processing Facility ( z/TPF)
IBM Cloud Pak for Security
IBM Fusion HCI
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Rational ClearQuest
Tenable Nessus
IBM Netezza Performance Server
IBM Automation Decision Services
Service Interconnect
Multicluster GlobalHub
Data Lakehouse
IBM Process Mining
IBM MQ Operator
Red Hat Advanced Cluster Management for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Spectrum Control
OpenShift Logging
IBM Rational Build Forge
IBM MQ for HPE NonStop
IBM Maximo Application Suite
IBM Rational ClearCase
IBM QRadar WinCollect Agent
IBM Cloud Pak for Business Automation
IBM Observability with Instana
Rapid Infrastructure Automation
Guardium Data Security Center (GDSC)
IBM Cloud Pak for Watson AIOps
Maximo Application Suite - Predict Component
Verify Identity Access Digital Credentials
HP-UX OpenSSL
Sterling Connect:Express for UNIX
QRadar App SDK
Data Observability by Databand Self-Hosted
Netezza Performance Server Replication Services
Security QRadar EDR
watsonx Assistant for IBM Cloud Pak for Data
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
SOAR QRadar Plugin App
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Maximo Application Suite - IoT Component
Maximo Application Suite - Edge Data Collector
IBM Virtualization Engine TS7700 3948-VED
System Storage Virtualization Engine TS7700 3948-VEF
IBM Netezza for Cloud Pak for Data
Business Automation Insights
QRadar Suite
IBM Security SOAR
IBM Cloud Pak System
IBM VIOS
Nessus Network Monitor
Red Hat OpenShift Container Platform
SecurityCenter
IBM Security Guardium
LANTIME Operating System Firmware (LTOS)
PowerProtect Cyber Recovery
Virtualization Engine TS7700 3957-VED
Nessus Agent
IBM Security Verify Access
Juniper Junos Space
Orion Platform
IBM App Connect Enterprise
BIG-IP LTM
Oracle Database Server
IBM InfoSphere Information Server
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
IBM Integrated Analytics System
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
openssl (Ubuntu package)
libssl3 (Ubuntu package)
openssl (Red Hat package)
openssl
openssl-doc
openssl-perl
openssl-libs
openssl-devel
openssl-help
openssl-debugsource
openssl-debuginfo
libssl3t64 (Ubuntu package)
openssl (Debian package)
libopenssl-3-fips-provider-debuginfo
libopenssl-3-fips-provider
openssl-3-debugsource
edk2 (Ubuntu package)
edk2-aarch64
edk2-help
edk2-debuginfo
edk2-devel
edk2-ovmf
python3-edk2-devel
edk2-debugsource
edk2
edk2 (Red Hat package)
IBM Storage Scale System

How to mitigate CVE-2024-6119

Install updates from vendor's website.

OpenSSL - addressed in versions 3.0.15, 3.1.7, 3.2.3, 3.3.2
IBM Concert Software - update to 1.1.0
Rapid Infrastructure Automation - update to 1.1.5.3
QRadar Suite - update to 1.10.27.0
IBM Fusion HCI - update to 2.10.0
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.3
Nessus Network Monitor - update to 6.5.0
SecurityCenter - update to SC-202412.1
LANTIME Operating System Firmware (LTOS) - update to 7.08.016
Maximo Application Suite - Predict Component - update to 9.0.3
IBM Rational ClearQuest - addressed in versions 9.1.0.8, 10.0.7
Nessus Agent - update to 10.7.3
Tenable Nessus - addressed in versions 10.7.6, 10.8.3
IBM Netezza Performance Server - update to 11.2.3.3
IBM App Connect Enterprise - addressed in versions 12.0.12.8, 13.0.1.1
PowerProtect Cyber Recovery - update to 19.18.0.2
Oracle Database Server - update to 23.6
IBM Automation Decision Services - update to 24.0.0.0.4
Juniper Junos Space - update to 24.1R2
Orion Platform - update to 2025.1
HP-UX OpenSSL - update to A.03.00.15.001
Service Interconnect - addressed in versions 1, 1.4
IBM Integrated Analytics System - update to 1.0.30.0
Multicluster GlobalHub - update to 1.2.1
Data Lakehouse - update to 1.3.0.0
Sterling Connect:Express for UNIX - update to 1.5.0.17010
IBM Process Mining - update to 1.15.0 IF004
IBM MQ Operator - addressed in versions 2.0.28, 3.2.6, 3.3.0, 9.4.1.0-r1
QRadar App SDK - update to 2.2.4
Multicluster Engine for Kubernetes - update to 2.7.2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.11.3, 2.11.4, 2.12.0, 2.12.1
Data Observability by Databand Self-Hosted - addressed in versions 3.0, 3.1, 3.2, 3.3
openssl (Ubuntu package) - addressed in versions 3.0.2-0ubuntu1.18, 3.0.13-0ubuntu3.4
libssl3 (Ubuntu package) - update to 3.0.2-0ubuntu1.18
Netezza Performance Server Replication Services - update to 3.0.5.1
openssl (Red Hat package) - update to 3.0.7-28.el9_4
openssl - update to 3.0.12-8
openssl-doc - update to 3.0.12-8
openssl-perl - update to 3.0.12-8
openssl-libs - update to 3.0.12-8
openssl-devel - update to 3.0.12-8
openssl-perl - update to 3.0.12-11
openssl-help - update to 3.0.12-11
openssl-libs - update to 3.0.12-11
openssl-devel - update to 3.0.12-11
openssl-debugsource - update to 3.0.12-11
openssl-debuginfo - update to 3.0.12-11
openssl - update to 3.0.12-11
libssl3t64 (Ubuntu package) - update to 3.0.13-0ubuntu3.4
openssl (Debian package) - update to 3.0.14-1~deb12u2
openssl - update to 3.1.4-4.fc39
libopenssl-3-fips-provider-debuginfo - update to 3.1.4-150600.5.15.1
libopenssl-3-fips-provider - update to 3.1.4-150600.5.15.1
openssl-3-debugsource - update to 3.1.4-150600.5.15.1
Security QRadar EDR - update to 3.12.14
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.7
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.8
watsonx Assistant for IBM Cloud Pak for Data - update to 4.8.8
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.13.12, 4.14.11, 4.16.3
Red Hat OpenShift Container Platform - addressed in versions 4.16.15, 4.16.16, 4.17.0, 4.17.1, 4.17.4, 4.17.8
App Connect Enterprise Certified Container - addressed in versions 5.0.22, 12.0.6, 12.6.0
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
IBM Spectrum Control - update to 5.4.13
SOAR QRadar Plugin App - update to 5.6.0
OpenShift Logging - addressed in versions 5.8.13, 5.8.14, 5.9.7, 5.9.8, 6.0.1
IBM Storage Scale System - addressed in versions 6.1.9.5, 6.2.2.0
IBM Rational Build Forge - update to 8.0.0.27
IBM MQ for HPE NonStop - update to 8.1.0.26
Storage Protect Client - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
Maximo Application Suite - IoT Component - addressed in versions 8.7.19, 8.8.15, 9.0.5
IBM Maximo Application Suite - addressed in versions 8.10.19, 8.11.16, 9.0.4
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.13, 9.0.5
Virtualization Engine TS7700 3957-VED - addressed in versions 8.54.1.27 VTD_EXEC.279, 8.54.2.17, 8.60.0.115 VTD_EXEC.279
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.54.1.27 VTD_EXEC.279, 8.54.2.17, 8.60.0.115 VTD_EXEC.279
System Storage Virtualization Engine TS7700 3948-VEF - update to 8.60.0.115 VTD_EXEC.279
IBM Rational ClearCase - addressed in versions 9.1.0.8, 10.0.1.3, 11.0.0.3
IBM QRadar WinCollect Agent - update to 10.1.12
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
IBM Security Guardium - update to 12.0p30
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
Business Automation Insights - addressed in versions 24.0.0.0.2, 24.0.1.0.1
IBM Security SOAR - update to 51.0.4.1
IBM Observability with Instana - update to 284
edk2 (Ubuntu package) - addressed in versions 2022.02-3ubuntu0.22.04.4, 2022.02-3ubuntu0.22.04.5, 2024.02-2ubuntu0.6, 2024.02-2ubuntu0.7, 2025.02-3ubuntu2.2
edk2-aarch64 - update to 202308-10
edk2-help - update to 202308-10
edk2-debuginfo - update to 202308-10
edk2-devel - update to 202308-10
edk2-ovmf - update to 202308-10
python3-edk2-devel - update to 202308-10
edk2-debugsource - update to 202308-10
edk2 - update to 202308-10
edk2 (Red Hat package) - update to 20231122-6.el9_4.4

External References

Related Security Bulletins