Out-of-bounds write in OpenSSL - CVE-2024-9143

 

Out-of-bounds write in OpenSSL - CVE-2024-9143

Published: October 16, 2024 / Updated: February 11, 2025


Vulnerability identifier: #VU98757
CSH Severity: Low
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-9143
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when using the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial. A remote attacker can send specially crafted input to the server, trigger an out-of-bounds write and perform a denial of service (DoS) attack.

Note, the vulnerability can be exploited against the application in rare cases only that involve "exotic" curve encoding.


Affected software

OpenSSL
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
IBM i
Slackware Linux
Web and Scripting Module
Basesystem Module
openEuler
Ubuntu
Anolis OS
Oracle Solaris
Sensor Proxy
Tenable Identity Exposure (formerly Tenable.ad)
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Tivoli Netcool Impact
IBM Rational Build Forge
IBM Rational ClearQuest
IBM Rational ClearCase
Oracle HTTP Server
IBM Automation Decision Services
Oracle Communications Cloud Native Core Certificate Management
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
IBM Sterling Connect:Direct for UNIX
IBM Sterling Connect:Direct Web Services
Session Smart Router
IBM MQ
IBM Planning Analytics Workspace
Data Product Hub
Oracle Business Intelligence Enterprise Edition
IBM OpenPages with Watson
DevOps Code ClearCase
DB2 Query Management Facility
IBM Cloud Pak for Watson AIOps
IBM Sterling Connect:Direct for Microsoft Windows
IBM Semeru Runtimes
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
Planning Analytics Local
PeopleSoft Enterprise PeopleTools
Oracle Fusion Middleware
IBM Cloud Pak System
Nessus Network Monitor
JD Edwards EnterpriseOne Tools
Communications Unified Assurance
SecurityCenter
Splunk Universal Forwarder
IBM InfoSphere Information Server
PowerProtect Cyber Recovery
Siebel CRM Deployment
Orion Platform
IBM Integrated Analytics System
openssl-libs
openssl-help
openssl-devel
openssl-debugsource
openssl-debuginfo
openssl
openssl-perl
openssl-solibs
libssl1.1 (Ubuntu package)
openssl (Ubuntu package)
libssl3 (Ubuntu package)
openssl-doc
libssl3t64 (Ubuntu package)
libopenssl-fips-provider
libopenssl-devel
libopenssl-3-fips-provider
libopenssl3-debuginfo
libopenssl3-32bit-debuginfo
libopenssl-3-fips-provider-32bit
libopenssl3-32bit
libopenssl-3-fips-provider-32bit-debuginfo
openssl-3-debugsource
libopenssl3
openssl-3
libopenssl-3-devel
libopenssl-3-fips-provider-debuginfo
openssl-3-debuginfo
nodejs24-devel
nodejs24-docs
nodejs24-debuginfo
nodejs24
nodejs24-debugsource
npm24
edk2 (Ubuntu package)
edk2
python3-edk2-devel
edk2-ovmf
edk2-help
edk2-aarch64
edk2-devel
edk2-debugsource
edk2-debuginfo
Rational Business Developer (RBD)
IBM CICS TX Advanced
IBM App Connect Enterprise

How to mitigate CVE-2024-9143

Install update from vendor's website.

OpenSSL - addressed in versions 1.0.2zl, 1.1.1zb, 3.0.16, 3.1.8, 3.2.4, 3.3.3
Sensor Proxy - update to 1.0.12
IBM Planning Analytics Workspace - addressed in versions 2.0.103, 2.1.10
Planning Analytics Local - addressed in versions 2.0.9.21, 2.1.10
IBM Cloud Pak System - update to 2.3.5.1
Tenable Identity Exposure (formerly Tenable.ad) - update to 3.77.11
Data Product Hub - update to 5.1.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
Nessus Network Monitor - update to 6.5.1
SecurityCenter - update to SC-202504.2
IBM Tivoli Netcool Impact - update to 7.1.0.36
IBM Rational Build Forge - update to 8.0.0.28
IBM Rational ClearQuest - addressed in versions 9.1.0.8, 10.0.7
IBM Rational ClearCase - addressed in versions 9.1.0.9, 10.0.1.4
Splunk Universal Forwarder - addressed in versions 9.1.10, 9.2.7, 9.3.5, 9.4.3
DevOps Code ClearCase - update to 11.0.0.4
PowerProtect Cyber Recovery - update to 19.18.0.2
IBM Automation Decision Services - update to 24.0.0.0.4
Orion Platform - addressed in versions 2025.2, 2025.2.1
IBM Integrated Analytics System - update to 1.0.30.0
openssl-libs - addressed in versions 1.1.1f-38, 1.1.1m-39, 1.1.1wa-10, 3.0.12-12
openssl-help - addressed in versions 1.1.1f-38, 1.1.1m-39, 1.1.1wa-10, 3.0.12-12
openssl-devel - addressed in versions 1.1.1f-38, 1.1.1m-39, 1.1.1wa-10, 3.0.12-12
openssl-debugsource - addressed in versions 1.1.1f-38, 1.1.1m-39, 1.1.1wa-10, 3.0.12-12
openssl-debuginfo - addressed in versions 1.1.1f-38, 1.1.1m-39, 1.1.1wa-10, 3.0.12-12
openssl - addressed in versions 1.1.1f-38, 1.1.1m-39, 1.1.1wa-10, 3.0.12-12
openssl-perl - addressed in versions 1.1.1m-39, 1.1.1wa-10, 3.0.12-12
openssl-solibs - update to 1.1.1zb
openssl - update to 1.1.1zb
libssl1.1 (Ubuntu package) - update to 1.1.1f-1ubuntu2.24
openssl (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.24, 3.0.2-0ubuntu1.19, 3.0.13-0ubuntu3.5, 3.3.1-2ubuntu2.1
libssl3 (Ubuntu package) - update to 3.0.2-0ubuntu1.19
openssl - update to 3.0.12-11
openssl-devel - update to 3.0.12-11
openssl-libs - update to 3.0.12-11
openssl-perl - update to 3.0.12-11
openssl-doc - update to 3.0.12-11
libssl3t64 (Ubuntu package) - addressed in versions 3.0.13-0ubuntu3.5, 3.3.1-2ubuntu2.1
libopenssl-fips-provider - update to 3.5.0-150700.3.4.1
libopenssl-devel - update to 3.5.0-150700.3.4.1
openssl - update to 3.5.0-150700.3.4.1
libopenssl-3-fips-provider - update to 3.5.0-150700.5.45.2
libopenssl3-debuginfo - update to 3.5.0-150700.5.45.2
libopenssl3-32bit-debuginfo - update to 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-32bit - update to 3.5.0-150700.5.45.2
libopenssl3-32bit - update to 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-32bit-debuginfo - update to 3.5.0-150700.5.45.2
openssl-3-debugsource - update to 3.5.0-150700.5.45.2
libopenssl3 - update to 3.5.0-150700.5.45.2
openssl-3 - update to 3.5.0-150700.5.45.2
libopenssl-3-devel - update to 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-debuginfo - update to 3.5.0-150700.5.45.2
openssl-3-debuginfo - update to 3.5.0-150700.5.45.2
IBM Tivoli Netcool System Service Monitors/Application Service Monitors - update to 4.0.1 SP14
IBM Cloud Pak for Watson AIOps - update to 4.8.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.8
IBM Decision Optimization for Cloud Pak for Data - addressed in versions 4.8.9, 5.1.2
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.1.0.4.121, 6.3.0.4.4, 6.4.0.1.5
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.27, 6.2.0.26
Session Smart Router - addressed in versions 6.2.10, 6.3.7
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.4.15, 6.4.0.0.5
IBM Semeru Runtimes - addressed in versions 8.0.432.0, 11.0.25.0, 17.0.13.0, 21.0.5.0, 23.0.1.0
Storage Protect Client - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
CICS Transaction Gateway for Multiplatforms - addressed in versions 9.1, 9.2.0.2, 9.3.0.0
CICS Transaction Gateway Desktop Edition - addressed in versions 9.1, 9.2.0.2, 9.3.0.0
IBM MQ - update to 9.4.2
Rational Business Developer (RBD) - addressed in versions 9.6.2, 9.7.2
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
Oracle Solaris - addressed in versions 11.3 ESU 36.34, 11.4 SRU 80
IBM App Connect Enterprise - addressed in versions 12.0.12.9, 13.0.2.0
nodejs24-devel - update to 24.18.1-150700.15.18.1
nodejs24-docs - update to 24.18.1-150700.15.18.1
nodejs24-debuginfo - update to 24.18.1-150700.15.18.1
nodejs24 - update to 24.18.1-150700.15.18.1
nodejs24-debugsource - update to 24.18.1-150700.15.18.1
npm24 - update to 24.18.1-150700.15.18.1
edk2 (Ubuntu package) - addressed in versions 2022.02-3ubuntu0.22.04.4, 2022.02-3ubuntu0.22.04.5, 2024.02-2ubuntu0.6, 2024.02-2ubuntu0.7, 2025.02-3ubuntu2.2
edk2 - update to 202011-26
python3-edk2-devel - update to 202011-26
edk2-ovmf - update to 202011-26
edk2-help - update to 202011-26
edk2-aarch64 - update to 202011-26
edk2-devel - update to 202011-26
edk2-debugsource - update to 202011-26
edk2-debuginfo - update to 202011-26

External References

Related Security Bulletins