The maintainers of the OpenSSL project fixed a high-severity heap memory corruption issue, tracked as CVE-2022-2274, affecting the popular library.
This bug makes the RSA implementation with 2048 bit private keys incorrect on such machines and triggers a memory corruption during the computation. A remote attacker can exploit the memory corruption to achieve code execution on the machine while performing the computation.
The CVE-2022-2274 vulnerability was introduced in OpenSSL version 3.0.4 released on June 21, 2022.
“The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation.” reads the advisory published by the Project Maintainers. “SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86_64 architecture are affected by this issue.”
The OpenSSL software library allows secure communications over computer networks against eavesdropping or need to identify the party at the other end. OpenSSL contains an open-source implementation of the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols.
The vulnerability was reported to project maintainers on 22nd June 2022 by Ph.D. student Xi Ruoyao who also developed the patch.
The flaw has been addressed with the release of OpenSSL version 3.0.5, users of the library have to upgrade their instances as soon as possible.
In June, the security expert Guido Vranken discovered a remote memory-corruption vulnerability in the OpenSSL version 3.0.4 which was released on June 21, 2022.
Follow me on Twitter: @securityaffairs and Facebook
[adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, encryption)
[adrotate banner=”5″]
[adrotate banner=”13″]
On day two of Pwn2Own Berlin 2025, participants earned $435,000 for demonstrating zero-day in SharePoint,…
New botnet HTTPBot is targeting China's gaming, tech, and education sectors, cybersecurity researchers warn. NSFOCUS …
Meta plans to train AI on EU user data from May 27 without consent; privacy…
Over half of firms adopted AI in 2024, but cloud tools like Azure OpenAI raise…
Google released emergency security updates to fix a Chrome vulnerability that could lead to full…
Nova Scotia Power confirmed a data breach involving the theft of sensitive customer data after…
This website uses cookies.