Executive brief
A vulnerability in the OpenSSL encryption library could allow attackers to compromise the confidentiality of encrypted data. The issue affects specific technical functions used by developers to initialize encryption settings, potentially causing the system to use weak or repetitive security keys. This could allow an unauthorized party to decrypt sensitive communications or data that was intended to be protected.
Technical details
A vulnerability exists in OpenSSL 3.0 and 3.1 when calling EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2(), or EVP_CipherInit_ex2(). The OSSL_PARAM array is processed after the key and IV have been established, meaning changes to 'keylen' or 'ivlen' parameters do not take effect as intended. This leads to truncation or overreads of these values, specifically impacting RC2, RC4, RC5, CCM, GCM, and OCB cipher modes. In CCM, GCM, and OCB modes, IV truncation can lead to IV reuse, breaking the confidentiality of the cipher. While the OpenSSL SSL/TLS implementation and FIPS providers are not affected, custom applications using these specific APIs are vulnerable. Users should upgrade to OpenSSL 3.0.12 or 3.1.4.
Affected products
- OpenSSL Foundation OpenSSL 3.0.0 to 3.0.11, 3.1.0 to 3.1.3
Timeline
- 2022-12-03: other: Issue originally reported but not recognized as a security vulnerability
- 2023-09-21: other: Vulnerability reported to OpenSSL by Tony Battersby
- 2023-10-24: advisory: OpenSSL Security Advisory published
- 2023-10-24: patched: OpenSSL 3.0.12 and 3.1.4 released
References
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=0df40630850fb2740e6be6890bb905d3fc623b2d
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=5f69f5c65e483928c4b28ed16af6e5742929f1ee
- https://www.openssl.org/news/secadv/20231024.txt
- http://www.openwall.com/lists/oss-security/2023/10/24/1
- https://security.netapp.com/advisory/ntap-20231027-0010/
- https://security.netapp.com/advisory/ntap-20240201-0003/
- https://security.netapp.com/advisory/ntap-20240201-0004/