Executive brief
OpenSSL is a widely used security library that enables encrypted communications for websites and applications. A flaw in how it handles certain network protocol negotiations could allow an attacker to cause a service crash or potentially steal up to 255 bytes of private memory data. This issue primarily affects applications with specific configuration errors or those using the older, deprecated NPN protocol.
Technical details
A buffer overread exists in the SSL_select_next_proto function when it is called with a zero-length client protocols buffer. The function fails to validate the buffer length and, in the event of no protocol overlap, returns a pointer to memory immediately following the empty buffer. This typically occurs during ALPN or NPN negotiation callbacks. While libssl prevents this in standard ALPN usage, custom application logic or NPN implementations that pass a 0-length list are vulnerable. An attacker could potentially receive up to 255 bytes of arbitrary memory from the process. The fix implements stricter length checking for both client and server protocol lists.
Affected products
- OpenSSL OpenSSL 3.3, 3.2, 3.1, 3.0, 1.1.1, 1.0.2
Timeline
- 2024-06-27: advisory: OpenSSL Security Advisory published
- 2024-06-27: disclosed
References
- https://github.com/openssl/openssl/commit/4ada436a1946cbb24db5ab4ca082b69c1bc10f37
- https://github.com/openssl/openssl/commit/99fb785a5f85315b95288921a321a935ea29a51e
- https://github.com/openssl/openssl/commit/cf6f91f6121f4db167405db2f0de410a456f260c
- https://github.com/openssl/openssl/commit/e86ac436f0bd54d4517745483e2315650fae7b2c
- https://github.openssl.org/openssl/extended-releases/commit/9947251413065a05189a63c9b7a6c1d4e224c21c
- https://github.openssl.org/openssl/extended-releases/commit/b78ec0824da857223486660177d3b1f255c65d87
- https://www.openssl.org/news/secadv/20240627.txt