REDHAT-BUG-2254426: Medium severity OpenSSL OpenSSL vulnerability

Published Dec 13, 2023
·
Updated

Description: The fix for CVE-2020-25657 is not addressing the leakage in the RSA decryption. Because of the API design, the fix is generally not believed to be possible to be fully addressed. The issue can be mitigated by using a cryptographic backend that implements implicit rejection (Marvin workaround). Only applications that use RSA decryption with PKCS#1 v1.5 padding are affected.

References: https://gitlab.com/m2crypto/m2crypto/-/issues/342 https://people.redhat.com/~hkario/marvin/ https://github.com/openssl/openssl/pull/13817

Affected Software

2 affected components
OpenSSL OpenSSL
M2Crypto M2Crypto

Event History

Dec 13, 2023
Data Sourced
via Red Hat·09:20 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2254426?

The severity of REDHAT-BUG-2254426 is assessed to be high due to potential RSA decryption leakage.

2

How do I fix REDHAT-BUG-2254426?

Currently, there is no complete fix for REDHAT-BUG-2254426, but mitigation strategies should be employed, such as patching and updating to secure versions.

3

Which software is affected by REDHAT-BUG-2254426?

REDHAT-BUG-2254426 affects the OpenSSL and M2Crypto software packages.

4

Is it safe to use OpenSSL with REDHAT-BUG-2254426 vulnerability?

Using OpenSSL with REDHAT-BUG-2254426 is risky and should be done with caution until proper mitigations are applied.

5

What are the risks associated with REDHAT-BUG-2254426?

The risks of REDHAT-BUG-2254426 include potential data exposure and security breaches due to RSA decryption leakage.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203