REDHAT-BUG-2430380: Low severity OpenSSL OpenSSL vulnerability
This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application.
The line-buffering BIO filter (BIOflinebuffer) is not used by default in TLS/SSL data paths. In OpenSSL command-line applications, it is typically only pushed onto stdout/stderr on VMS systems. Third-party applications that explicitly use this filter with a BIO chain that can short-write and that write large, newline-free data influenced by an attacker would be affected. However, the circumstances where this could happen are unlikely to be under attacker control, and BIOflinebuffer is unlikely to be handling non-curated data controlled by an attacker. For that reason the issue was assessed as Low severity.
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the BIO implementation is outside the OpenSSL FIPS module boundary.
OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.
OpenSSL 3.6 users should upgrade to OpenSSL 3.6.1.
OpenSSL 3.5 users should upgrade to OpenSSL 3.5.5.
OpenSSL 3.4 users should upgrade to OpenSSL 3.4.4.
OpenSSL 3.3 users should upgrade to OpenSSL 3.3.6.
OpenSSL 3.0 users should upgrade to OpenSSL 3.0.19.
OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1ze (premium support customers only).
OpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zn (premium support customers only).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in OpenSSL 1.0.2zn - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in OpenSSL 1.1.1ze - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in OpenSSL 3.0.19 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in OpenSSL 3.3.6 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in OpenSSL 3.4.4 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in OpenSSL 3.5.5 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in OpenSSL 3.6.1
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2430380?
The severity of REDHAT-BUG-2430380 is high due to the potential for memory corruption leading to Denial of Service.
How do I fix REDHAT-BUG-2430380?
To fix REDHAT-BUG-2430380, you should update OpenSSL to a version that addresses the vulnerability.
What applications are affected by REDHAT-BUG-2430380?
Applications utilizing OpenSSL versions ranging from 1.0.2 to 3.6 are affected by REDHAT-BUG-2430380.
What is the impact of REDHAT-BUG-2430380 on services?
The impact of REDHAT-BUG-2430380 includes potential application crashes and resultant Denial of Service.
Is there a workaround for REDHAT-BUG-2430380?
There is no specific workaround for REDHAT-BUG-2430380; updating OpenSSL is the recommended action.