openssl: freelist misuse causing a possible use-after-free
Published Apr 14, 2014
4.0
MEDIUMCVSS 2.0
EPSS 34.13%
Description
Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.
Affected products
No data.
Configuration 3
- 19
- 20
Configuration 4
- 12
- 12
- 12
- 12
No data.
Red Hat Enterprise Linux 6
openssl-0:1.0.1e-16.el6_5.14
Fixed · RHSA-2014:0625
Red Hat Enterprise Linux 7
openssl-1:1.0.1e-34.el7_0.3
Fixed · RHSA-2014:0679
Red Hat Storage 2.1
openssl-0:1.0.1e-16.el6_5.14
Fixed · RHSA-2014:0628
Red Hat Enterprise Linux 5
openssl
Not affected
Red Hat Enterprise Linux 5
openssl097a
Not affected
Red Hat Enterprise Linux 6
guest-images
Not affected
Red Hat Enterprise Linux 6
openssl098e
Not affected
Red Hat Enterprise Linux 7
openssl098e
Not affected
Red Hat Enterprise Virtualization 3
mingw-virt-viewer
Not affected
Red Hat JBoss Enterprise Application Platform 5
openssl
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Not affected
Red Hat JBoss Enterprise Web Server 1
openssl
Not affected
Red Hat JBoss Enterprise Web Server 2
openssl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | openssl-0:1.0.1e-16.el6_5.14 | Fixed | RHSA-2014:0625 |
| Red Hat Enterprise Linux 7 | openssl-1:1.0.1e-34.el7_0.3 | Fixed | RHSA-2014:0679 |
| Red Hat Storage 2.1 | openssl-0:1.0.1e-16.el6_5.14 | Fixed | RHSA-2014:0628 |
| Red Hat Enterprise Linux 5 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Not affected | n/a |
| Red Hat Enterprise Linux 6 | guest-images | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Virtualization 3 | mingw-virt-viewer | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 1 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | openssl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the openssl packages shipped with Red Hat Enterprise Linux 5.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:N/C:N/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (43 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 34.13% (0.34132) | 98.36th | v5 (v2026.06.15) |
| Jun 15, 2026 | 34.13% (0.34132) | 98.18th | v5 (v2026.06.15) |
| Jun 4, 2026 | 19.07% (0.19072) | 95.46th | v4 (v2025.03.14) |
| May 31, 2026 | 15.76% (0.15758) | 94.84th | v4 (v2025.03.14) |
| May 21, 2026 | 14.70% (0.14699) | 94.57th | v4 (v2025.03.14) |
| May 18, 2026 | 12.94% (0.12942) | 94.14th | v4 (v2025.03.14) |
| May 11, 2026 | 14.10% (0.14104) | 94.41th | v4 (v2025.03.14) |
| Mar 28, 2026 | 10.73% (0.10730) | 93.29th | v4 (v2025.03.14) |
| Mar 4, 2026 | 12.24% (0.12240) | 93.70th | v4 (v2025.03.14) |
| Mar 1, 2026 | 14.04% (0.14044) | 94.23th | v4 (v2025.03.14) |
| Feb 4, 2026 | 10.73% (0.10730) | 93.14th | v4 (v2025.03.14) |
| Feb 1, 2026 | 12.35% (0.12351) | 93.72th | v4 (v2025.03.14) |
| Jan 4, 2026 | 10.73% (0.10730) | 93.08th | v4 (v2025.03.14) |
| Jan 1, 2026 | 12.35% (0.12351) | 93.69th | v4 (v2025.03.14) |
| Dec 28, 2025 | 10.73% (0.10730) | 93.08th | v4 (v2025.03.14) |
| Dec 27, 2025 | 7.70% (0.07695) | 91.64th | v4 (v2025.03.14) |
| Dec 11, 2025 | 10.32% (0.10320) | 92.92th | v4 (v2025.03.14) |
| Dec 4, 2025 | 11.78% (0.11781) | 93.43th | v4 (v2025.03.14) |
| Dec 1, 2025 | 13.53% (0.13531) | 93.99th | v4 (v2025.03.14) |
| Nov 25, 2025 | 12.24% (0.12240) | 93.57th | v4 (v2025.03.14) |
| Nov 18, 2025 | 10.32% (0.10320) | 92.41th | v4 (v2025.03.14) |
| Oct 28, 2025 | 14.64% (0.14635) | 94.17th | v4 (v2025.03.14) |
| Oct 27, 2025 | 10.66% (0.10661) | 92.97th | v4 (v2025.03.14) |
| Oct 1, 2025 | 14.73% (0.14731) | 94.29th | v4 (v2025.03.14) |
| Sep 4, 2025 | 10.66% (0.10661) | 93.03th | v4 (v2025.03.14) |
| Sep 1, 2025 | 11.73% (0.11733) | 93.48th | v4 (v2025.03.14) |
| Aug 4, 2025 | 10.66% (0.10661) | 93.00th | v4 (v2025.03.14) |
| Aug 1, 2025 | 11.73% (0.11733) | 93.45th | v4 (v2025.03.14) |
| Jul 30, 2025 | 10.66% (0.10661) | 92.99th | v4 (v2025.03.14) |
| Mar 30, 2025 | 13.80% (0.13801) | 93.68th | v4 (v2025.03.14) |
| Mar 29, 2025 | 18.95% (0.18945) | 92.30th | v4 (v2025.03.14) |
| Mar 17, 2025 | 14.08% (0.14084) | 93.83th | v4 (v2025.03.14) |
| Dec 17, 2024 | 31.97% (0.31975) | 97.02th | v3 (v2023.03.01) |
| May 5, 2024 | 2.90% (0.02897) | 90.71th | v3 (v2023.03.01) |
| Apr 12, 2024 | 12.45% (0.12453) | 95.33th | v3 (v2023.03.01) |
| Nov 25, 2023 | 13.22% (0.13223) | 94.99th | v3 (v2023.03.01) |
| Nov 7, 2023 | 10.79% (0.10790) | 94.48th | v3 (v2023.03.01) |
| Oct 9, 2023 | 3.10% (0.03102) | 89.89th | v3 (v2023.03.01) |
| May 8, 2023 | 3.26% (0.03255) | 89.79th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.36% (0.03364) | 89.89th | v3 (v2023.03.01) |
| Mar 6, 2023 | 15.26% (0.15261) | 95.93th | v2 (v2022.01.01) |
| Apr 1, 2022 | 15.26% (0.15261) | 95.56th | v2 (v2022.01.01) |
| Feb 4, 2022 | 15.26% (0.15261) | 91.34th | v2 (v2022.01.01) |
References (87)
- http://advisories.mageia.org/MGASA-2014-0187.html x_refsource_CONFIRMThird Party Advisory
- http://ftp.openbsd.org/pub/OpenBSD/patches/5.5/common/004_openssl.patch.sig x_refsource_CONFIRMPatchThird Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629 x_refsource_CONFIRMThird Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=KB29195 x_refsource_CONFIRMPermissions Required
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140389274407904&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140389355508263&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140431828824371&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140448122410568&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140544599631400&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140621259019789&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140752315422991&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140904544427729&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=141658880509699&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2014/04/13/1 mailing-listx_refsource_MLISTMailing ListPatch
- http://seclists.org/fulldisclosure/2014/Dec/23 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://secunia.com/advisories/58337 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58713 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58939 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58977 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59162 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59287 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59300 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59301 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59342 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59413 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59437 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59438 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59440 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59450 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59490 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59655 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59666 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59669 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59721 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://security.gentoo.org/glsa/glsa-201407-05.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://support.citrix.com/article/CTX140876 x_refsource_CONFIRMThird Party Advisory
- http://svnweb.freebsd.org/ports/head/security/openssl/files/patch-ssl-s3_pkt.c?revision=351191&view=markup x_refsource_CONFIRMBroken Link
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140605-openssl vendor-advisoryx_refsource_CISCOThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21673137 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21676035 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21676062 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676419 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676529 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676655 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676879 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21676889 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21677527 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21677695 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21677828 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21677836 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21678167 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21683332 x_refsource_CONFIRMThird Party Advisory
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095754 x_refsource_CONFIRMBroken Link
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095755 x_refsource_CONFIRMBroken Link
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095756 x_refsource_CONFIRMBroken Link
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095757 x_refsource_CONFIRMBroken Link
- http://www.blackberry.com/btsc/KB36051 x_refsource_CONFIRMBroken Link
- http://www.fortiguard.com/advisory/FG-IR-14-018/ x_refsource_CONFIRMThird Party Advisory
- http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-345106.htm x_refsource_CONFIRMThird Party Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21676356 x_refsource_CONFIRMThird Party Advisory
- http://www.ibm.com/support/docview.wss?uid=swg24037783 x_refsource_CONFIRMThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:090 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:062 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.openbsd.org/errata55.html#004_openssl vendor-advisoryx_refsource_OPENBSDThird Party Advisory
- http://www.openssl.org/news/secadv_20140605.txt x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html x_refsource_CONFIRMThird Party Advisory
- http://www.securityfocus.com/archive/1/534161/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/66801 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.tedunangst.com/flak/post/analysis-of-openssl-freelist-reuse x_refsource_MISCThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2014-0006.html x_refsource_CONFIRMThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html x_refsource_CONFIRMThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2010-5298 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1087195 Issue Tracking
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05301946 x_refsource_CONFIRMThird Party Advisory
- https://kb.bluecoat.com/index?page=content&id=SA80 x_refsource_CONFIRMBroken Link
- https://kc.mcafee.com/corporate/index?page=content&id=SB10075 x_refsource_CONFIRMBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2010-5298
- https://rt.openssl.org/Ticket/Display.html?id=2167&user=guest&pass=guest x_refsource_MISCBroken Link
- https://rt.openssl.org/Ticket/Display.html?id=3265&user=guest&pass=guest x_refsource_MISCBroken Link
- https://www.cve.org/CVERecord?id=CVE-2010-5298
- https://www.novell.com/support/kb/doc.php?id=7015271 x_refsource_CONFIRMThird Party Advisory
- https://www.openssl.org/news/secadv_20140605.txt
Change history (0)
No recorded changes yet.