Out-of-bounds write in OpenSSL - CVE-2024-9143
Published: October 16, 2024 / Updated: February 11, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when using the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial. A remote attacker can send specially crafted input to the server, trigger an out-of-bounds write and perform a denial of service (DoS) attack.
Note, the vulnerability can be exploited against the application in rare cases only that involve "exotic" curve encoding.
Affected software
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
IBM i
Slackware Linux
Web and Scripting Module
Basesystem Module
openEuler
Ubuntu
Anolis OS
Oracle Solaris
Sensor Proxy
Tenable Identity Exposure (formerly Tenable.ad)
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Tivoli Netcool Impact
IBM Rational Build Forge
IBM Rational ClearQuest
IBM Rational ClearCase
Oracle HTTP Server
IBM Automation Decision Services
Oracle Communications Cloud Native Core Certificate Management
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
IBM Sterling Connect:Direct for UNIX
IBM Sterling Connect:Direct Web Services
Session Smart Router
IBM MQ
IBM Planning Analytics Workspace
Data Product Hub
Oracle Business Intelligence Enterprise Edition
IBM OpenPages with Watson
DevOps Code ClearCase
DB2 Query Management Facility
IBM Cloud Pak for Watson AIOps
IBM Sterling Connect:Direct for Microsoft Windows
IBM Semeru Runtimes
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
Planning Analytics Local
PeopleSoft Enterprise PeopleTools
Oracle Fusion Middleware
IBM Cloud Pak System
Nessus Network Monitor
JD Edwards EnterpriseOne Tools
Communications Unified Assurance
SecurityCenter
Splunk Universal Forwarder
IBM InfoSphere Information Server
PowerProtect Cyber Recovery
Siebel CRM Deployment
Orion Platform
IBM Integrated Analytics System
openssl-libs
openssl-help
openssl-devel
openssl-debugsource
openssl-debuginfo
openssl
openssl-perl
openssl-solibs
libssl1.1 (Ubuntu package)
openssl (Ubuntu package)
libssl3 (Ubuntu package)
openssl-doc
libssl3t64 (Ubuntu package)
libopenssl-fips-provider
libopenssl-devel
libopenssl-3-fips-provider
libopenssl3-debuginfo
libopenssl3-32bit-debuginfo
libopenssl-3-fips-provider-32bit
libopenssl3-32bit
libopenssl-3-fips-provider-32bit-debuginfo
openssl-3-debugsource
libopenssl3
openssl-3
libopenssl-3-devel
libopenssl-3-fips-provider-debuginfo
openssl-3-debuginfo
nodejs24-devel
nodejs24-docs
nodejs24-debuginfo
nodejs24
nodejs24-debugsource
npm24
edk2 (Ubuntu package)
edk2
python3-edk2-devel
edk2-ovmf
edk2-help
edk2-aarch64
edk2-devel
edk2-debugsource
edk2-debuginfo
Rational Business Developer (RBD)
IBM CICS TX Advanced
IBM App Connect Enterprise
How to mitigate CVE-2024-9143
Sensor Proxy - update to 1.0.12
IBM Planning Analytics Workspace - addressed in versions 2.0.103, 2.1.10
Planning Analytics Local - addressed in versions 2.0.9.21, 2.1.10
IBM Cloud Pak System - update to 2.3.5.1
Tenable Identity Exposure (formerly Tenable.ad) - update to 3.77.11
Data Product Hub - update to 5.1.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
Nessus Network Monitor - update to 6.5.1
SecurityCenter - update to SC-202504.2
IBM Tivoli Netcool Impact - update to 7.1.0.36
IBM Rational Build Forge - update to 8.0.0.28
IBM Rational ClearQuest - addressed in versions 9.1.0.8, 10.0.7
IBM Rational ClearCase - addressed in versions 9.1.0.9, 10.0.1.4
Splunk Universal Forwarder - addressed in versions 9.1.10, 9.2.7, 9.3.5, 9.4.3
DevOps Code ClearCase - update to 11.0.0.4
PowerProtect Cyber Recovery - update to 19.18.0.2
IBM Automation Decision Services - update to 24.0.0.0.4
Orion Platform - addressed in versions 2025.2, 2025.2.1
IBM Integrated Analytics System - update to 1.0.30.0
openssl-libs - addressed in versions 1.1.1f-38, 1.1.1m-39, 1.1.1wa-10, 3.0.12-12
openssl-help - addressed in versions 1.1.1f-38, 1.1.1m-39, 1.1.1wa-10, 3.0.12-12
openssl-devel - addressed in versions 1.1.1f-38, 1.1.1m-39, 1.1.1wa-10, 3.0.12-12
openssl-debugsource - addressed in versions 1.1.1f-38, 1.1.1m-39, 1.1.1wa-10, 3.0.12-12
openssl-debuginfo - addressed in versions 1.1.1f-38, 1.1.1m-39, 1.1.1wa-10, 3.0.12-12
openssl - addressed in versions 1.1.1f-38, 1.1.1m-39, 1.1.1wa-10, 3.0.12-12
openssl-perl - addressed in versions 1.1.1m-39, 1.1.1wa-10, 3.0.12-12
openssl-solibs - update to 1.1.1zb
openssl - update to 1.1.1zb
libssl1.1 (Ubuntu package) - update to 1.1.1f-1ubuntu2.24
openssl (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.24, 3.0.2-0ubuntu1.19, 3.0.13-0ubuntu3.5, 3.3.1-2ubuntu2.1
libssl3 (Ubuntu package) - update to 3.0.2-0ubuntu1.19
openssl - update to 3.0.12-11
openssl-devel - update to 3.0.12-11
openssl-libs - update to 3.0.12-11
openssl-perl - update to 3.0.12-11
openssl-doc - update to 3.0.12-11
libssl3t64 (Ubuntu package) - addressed in versions 3.0.13-0ubuntu3.5, 3.3.1-2ubuntu2.1
libopenssl-fips-provider - update to 3.5.0-150700.3.4.1
libopenssl-devel - update to 3.5.0-150700.3.4.1
openssl - update to 3.5.0-150700.3.4.1
libopenssl-3-fips-provider - update to 3.5.0-150700.5.45.2
libopenssl3-debuginfo - update to 3.5.0-150700.5.45.2
libopenssl3-32bit-debuginfo - update to 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-32bit - update to 3.5.0-150700.5.45.2
libopenssl3-32bit - update to 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-32bit-debuginfo - update to 3.5.0-150700.5.45.2
openssl-3-debugsource - update to 3.5.0-150700.5.45.2
libopenssl3 - update to 3.5.0-150700.5.45.2
openssl-3 - update to 3.5.0-150700.5.45.2
libopenssl-3-devel - update to 3.5.0-150700.5.45.2
libopenssl-3-fips-provider-debuginfo - update to 3.5.0-150700.5.45.2
openssl-3-debuginfo - update to 3.5.0-150700.5.45.2
IBM Tivoli Netcool System Service Monitors/Application Service Monitors - update to 4.0.1 SP14
IBM Cloud Pak for Watson AIOps - update to 4.8.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.8
IBM Decision Optimization for Cloud Pak for Data - addressed in versions 4.8.9, 5.1.2
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.1.0.4.121, 6.3.0.4.4, 6.4.0.1.5
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.27, 6.2.0.26
Session Smart Router - addressed in versions 6.2.10, 6.3.7
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.4.15, 6.4.0.0.5
IBM Semeru Runtimes - addressed in versions 8.0.432.0, 11.0.25.0, 17.0.13.0, 21.0.5.0, 23.0.1.0
Storage Protect Client - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
CICS Transaction Gateway for Multiplatforms - addressed in versions 9.1, 9.2.0.2, 9.3.0.0
CICS Transaction Gateway Desktop Edition - addressed in versions 9.1, 9.2.0.2, 9.3.0.0
IBM MQ - update to 9.4.2
Rational Business Developer (RBD) - addressed in versions 9.6.2, 9.7.2
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
Oracle Solaris - addressed in versions 11.3 ESU 36.34, 11.4 SRU 80
IBM App Connect Enterprise - addressed in versions 12.0.12.9, 13.0.2.0
nodejs24-devel - update to 24.18.1-150700.15.18.1
nodejs24-docs - update to 24.18.1-150700.15.18.1
nodejs24-debuginfo - update to 24.18.1-150700.15.18.1
nodejs24 - update to 24.18.1-150700.15.18.1
nodejs24-debugsource - update to 24.18.1-150700.15.18.1
npm24 - update to 24.18.1-150700.15.18.1
edk2 (Ubuntu package) - addressed in versions 2022.02-3ubuntu0.22.04.4, 2022.02-3ubuntu0.22.04.5, 2024.02-2ubuntu0.6, 2024.02-2ubuntu0.7, 2025.02-3ubuntu2.2
edk2 - update to 202011-26
python3-edk2-devel - update to 202011-26
edk2-ovmf - update to 202011-26
edk2-help - update to 202011-26
edk2-aarch64 - update to 202011-26
edk2-devel - update to 202011-26
edk2-debugsource - update to 202011-26
edk2-debuginfo - update to 202011-26
External References
- https://openssl-library.org/news/secadv/20241016.txt
- https://github.com/openssl/openssl/commit/c0d3e4d32d2805f49bec30547f225bc4d092e1f4
- https://github.com/openssl/openssl/commit/bc7e04d7c8d509fb78fc0e285aa948fb0da04700
- https://github.com/openssl/openssl/commit/fdf6723362ca51bd883295efe206cb5b1cfa5154
- https://github.com/openssl/openssl/commit/72ae83ad214d2eef262461365a1975707f862712
- https://github.openssl.org/openssl/extended-releases/commit/8efc0cbaa8ebba8e116f7b81a876a4123594d86a
- https://github.openssl.org/openssl/extended-releases/commit/9d576994cec2b7aa37a91740ea7e680810957e41
Related Security Bulletins
- Denial of service in OpenSSL
- Slackware Linux update for openssl
- IBM Integrated Analytics System update for OpenSSL
- IBM Integrated Analytics System update for OpenSSL
- openEuler 22.03 LTS SP4 update for openssl
- openEuler 24.03 LTS update for openssl
- openEuler 22.03 LTS SP1 update for openssl
- openEuler 22.03 LTS SP3 update for openssl
- openEuler 20.03 LTS SP4 update for openssl
- Multiple vulnerabilities in IBM Semeru Runtime
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM Data Product Hub
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in IBM Db2 Query Management Facility
- Multiple vulnerabilities in IBM Sterling Connect:Direct for Microsoft Windows
- Out-of-bounds write in Oracle Communications Cloud Native Core Certificate Management
- IBM Tivoli Netcool Impact update for OpenSSL
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Ubuntu update for openssl
- IBM Sterling Connect:Direct Web Services update for OpenSSL
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms and CICS Transaction Gateway Desktop Edition
- Ubuntu update for openssl
- Multiple vulnerabilities in IBM Sterling Connect:Direct for Unix
- Multiple vulnerabilities in IBM MQ
- IBM Tivoli Netcool System Service Monitors/Application Service Monitors update for OpenSSL
- openEuler update for edk2
- Oracle Solaris update for third-party components
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in Oracle HTTP Server
- Tenable Security Center update for third-party components
- Multiple vulnerabilities in IBM CICS TX Advanced
- Tenable Identity Exposure update for third-party components
- Tenable Sensor Proxy update for third-party components
- IBM InfoSphere Information Server update for OpenSSL
- Multiple vulnerabilities in IBM Planning Analytics
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in Tenable Network Monitor
- Anolis OS update for openssl
- Multiple vulnerabilities in SolarWinds Platform
- Multiple vulnerabilities in IBM Rational Build Forge
- Splunk Universal Forwarder update for third-party components
- Multiple vulnerabilities in Communications Unified Assurance
- Out-of-bounds write in Oracle Fusion Middleware
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in IBM i
- Multiple vulnerabilities in SolarWinds Platform
- Multiple vulnerabilities in IBM Automation Decision Services
- IBM Rational ClearQuest update for OpenSSL
- IBM DevOps Code ClearCase update for openssl
- IBM Rational Business Developer update for OpenSSL
- Out-of-bounds write in IBM OpenPages
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Ubuntu update for edk2
- Ubuntu update for edk2
- Multiple vulnerabilities in IBM Automation Decision Services
- Multiple vulnerabilities in Siebel CRM Deployment
- Juniper Session Smart Router update for third-party components
- Multiple vulnerabilities in IBM Storage Protect Backup-Archive Client, IBM Storage Protect for Virtual Environments and IBM Storage Protect for Space Management
- Multiple vulnerabilities in IBM Watson Knowledge Catalog on-prem
- Multiple vulnerabilities in IBM Cloud Pak System
- SUSE update for openssl, openssl-3