Executive brief
OpenSSL, a widely used security library for encrypting internet communications, contains a flaw on specific PowerPC-based hardware. An attacker could potentially trigger this flaw during a secure connection (TLS) handshake to corrupt the memory of the server application. This could lead to incorrect calculations, application crashes, or in rare cases, allow an attacker to gain control over the affected process.
Technical details
A bug exists in the OpenSSL POLY1305 MAC implementation specifically for PowerPC platforms supporting PowerISA 2.07 (vector instructions). The vulnerability is caused by the implementation restoring vector registers in a different order than they were saved, leading to register corruption upon returning to the caller. An attacker can trigger this by influencing the choice of the CHACHA20-POLY1305 AEAD cipher suite during a TLS 1.2 or 1.3 handshake. While the most likely outcome is a denial of service (crash) or incorrect application calculations, it could theoretically lead to remote code execution if the corrupted registers are used for pointer storage. The FIPS provider is unaffected as it does not implement POLY1305.
Affected products
- OpenSSL Foundation OpenSSL 3.0.0 to 3.0.12, 3.1.0 to 3.1.4, 3.2.0
Timeline
- 2023-10-09: disclosed: Reported to OpenSSL by Sverker Eriksson (Ericsson)
- 2024-01-09: advisory: OpenSSL Security Advisory published
- 2024-01-09: patched: Fixes available in OpenSSL git repository commits 5b139f95, f3fc5808, and 050d263
References
- https://github.com/openssl/openssl/commit/050d26383d4e264966fb83428e72d5d48f402d35
- https://github.com/openssl/openssl/commit/5b139f95c9a47a55a0c54100f3837b1eee942b04
- https://github.com/openssl/openssl/commit/f3fc5808fe9ff74042d639839610d03b8fdcc015
- https://www.openssl.org/news/secadv/20240109.txt
- http://www.openwall.com/lists/oss-security/2024/03/11/1
- https://security.netapp.com/advisory/ntap-20240216-0009/
- https://security.netapp.com/advisory/ntap-20240426-0008/