CVE-2015-3196: Race Condition

Published Dec 4, 2015
·
Updated

ssl/s3clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.

Other sources

The following was reported by OpenSSL upstream:

If PSK identity hints are received by a multi-threaded client then the values are wrongly updated in the parent SSLCTX structure. This can result in a race condition potentially leading to a double free of the identify hint data.

This issue was fixed in OpenSSL 1.0.2d and 1.0.1p but has not been previously listed in an OpenSSL security advisory. This issue also affects OpenSSL 1.0.0 and has not been previously fixed in an OpenSSL 1.0.0 release.

OpenSSL 1.0.2 users should upgrade to 1.0.2d OpenSSL 1.0.1 users should upgrade to 1.0.1p OpenSSL 1.0.0 users should upgrade to 1.0.0t

The fix for this issue can be identified in the OpenSSL git repository by commit ids 3c66a669dfc7 (1.0.2), d6be3124f228 (1.0.1) and 1392c238657e (1.0.0).

The fix was developed by Dr. Stephen Henson of the OpenSSL development team.

Affected Software

67 affected componentsFixes available
redhat/openssl<1.0.0
1.0.0
redhat/openssl<1.0.2
1.0.2
HP IceWall SSO=10.0
HP IceWall SSO Agent Option=10.0
OpenSSL OpenSSL=1.0.0
OpenSSL OpenSSL=1.0.0a
OpenSSL OpenSSL=1.0.0b
OpenSSL OpenSSL=1.0.0c
OpenSSL OpenSSL=1.0.0d
OpenSSL OpenSSL=1.0.0e
OpenSSL OpenSSL=1.0.0f
OpenSSL OpenSSL=1.0.0g
OpenSSL OpenSSL=1.0.0h
OpenSSL OpenSSL=1.0.0i
OpenSSL OpenSSL=1.0.0j
OpenSSL OpenSSL=1.0.0k
OpenSSL OpenSSL=1.0.0l
OpenSSL OpenSSL=1.0.0m
OpenSSL OpenSSL=1.0.0n
OpenSSL OpenSSL=1.0.0o
OpenSSL OpenSSL=1.0.0p
OpenSSL OpenSSL=1.0.0q
OpenSSL OpenSSL=1.0.0r
OpenSSL OpenSSL=1.0.0s
OpenSSL OpenSSL=1.0.1
OpenSSL OpenSSL=1.0.1a
OpenSSL OpenSSL=1.0.1b
OpenSSL OpenSSL=1.0.1c
OpenSSL OpenSSL=1.0.1d
OpenSSL OpenSSL=1.0.1e
OpenSSL OpenSSL=1.0.1f
OpenSSL OpenSSL=1.0.1g
OpenSSL OpenSSL=1.0.1h
OpenSSL OpenSSL=1.0.1i
OpenSSL OpenSSL=1.0.1j
OpenSSL OpenSSL=1.0.1k
OpenSSL OpenSSL=1.0.1l
OpenSSL OpenSSL=1.0.1m
OpenSSL OpenSSL=1.0.1n
OpenSSL OpenSSL=1.0.1o
Oracle VM VirtualBox>=4.3.0<=4.3.35
Oracle VM VirtualBox>=5.0.0<=5.0.13
Fedoraproject Fedora=22
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.2
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Eus=6.7
redhat Enterprise Linux Server Eus=7.2
redhat Enterprise Linux Server Eus=7.3
redhat Enterprise Linux Server Eus=7.4
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Server Tus=7.2
redhat Enterprise Linux Server Tus=7.3
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
Canonical Ubuntu Linux=15.10
Debian Debian Linux=7.0
Debian Debian Linux=8.0

Event History

Dec 6, 2015
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2015-3196?

CVE-2015-3196 has a severity rating that is classified as 'Medium' due to its potential to cause denial of service.

2

How do I fix CVE-2015-3196?

To fix CVE-2015-3196, upgrade OpenSSL to version 1.0.0t or later, 1.0.1p or later, or 1.0.2d or later.

3

Which versions of OpenSSL are affected by CVE-2015-3196?

OpenSSL versions 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d are affected by CVE-2015-3196.

4

How can CVE-2015-3196 be exploited?

CVE-2015-3196 can be exploited by remote servers inducing a denial of service through crafted server responses, leading to a race condition and double free.

5

Is there a workaround for CVE-2015-3196 if I cannot update immediately?

Currently, the best practice is to apply the available patches as there are no known effective workarounds for CVE-2015-3196.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203