CVE-2022-4203: X.509 Name Constraints Read Buffer Overflow

Published Jan 25, 2023
·
Updated

A flaw was found in Open SSL. A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification, and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer.

Other sources

A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer.

The read buffer overrun might result in a crash which could lead to a denial of service attack. In theory it could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext) although we are not aware of any working exploit leading to memory contents disclosure as of the time of release of this advisory.

In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects.

NVD

Affected Software

5 affected componentsFixes available
redhat/openssl<1:3.0.1-47.el9_1
1:3.0.1-47.el9_1
redhat/openssl<1:3.0.1-46.el9_0
1:3.0.1-46.el9_0
rust/openssl-src>=300.0.0<300.0.12
300.0.12
debian/openssl
1.1.1w-0+deb11u11.1.1n-0+deb11u53.0.14-1~deb12u13.0.14-1~deb12u23.3.2-1
OpenSSL OpenSSL>=3.0.0<3.0.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/openssl to a version that resolves this vulnerability.

    Fixed in 1:3.0.1-47.el9_1
  2. Upgrade

    Upgrade redhat/openssl to a version that resolves this vulnerability.

    Fixed in 1:3.0.1-46.el9_0
  3. Upgrade

    Upgrade rust/openssl-src to a version that resolves this vulnerability.

    Fixed in 300.0.12
  4. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1n-0+deb11u5Fixed in 3.0.14-1~deb12u1Fixed in 3.0.14-1~deb12u2Fixed in 3.3.2-1

Event History

Jan 25, 2023
Data Sourced
via Red Hat·03:23 PM
DescriptionSeverityAffected Software
Feb 7, 2023
CVE Published
12:00 AM
Feb 8, 2023
Advisory Published
via GitHub·10:27 PM
Feb 24, 2023
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 21, 2024
Data Sourced
via Launchpad·12:35 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:50 AM
RemedyDescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is CVE-2022-4203?

CVE-2022-4203 is a vulnerability in OpenSSL that allows a read buffer overrun in X.509 certificate verification.

2

How does CVE-2022-4203 occur?

CVE-2022-4203 occurs during name constraint checking in X.509 certificate verification.

3

What is the severity of CVE-2022-4203?

The severity of CVE-2022-4203 is medium with a severity value of 4.9.

4

Which versions of OpenSSL are affected by CVE-2022-4203?

OpenSSL versions 3.0.0 to 3.0.8 are affected by CVE-2022-4203.

5

How can I fix CVE-2022-4203?

To fix CVE-2022-4203, update OpenSSL to version 3.0.1-47.el9_1 or higher.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203