Back

HIGH

openssl: OCSP Status Request extension unbounded memory growth

Published Sep 26, 2016

Description

Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.

Affected products

Remediation

Red Hat statement

TLS server applications using OpenSSL versions in Red Hat Enterprise Linux 6 and 7 are only affected if they enable OCSP stapling support. Applications not enabling OCSP stapling support are not affected. Few applications implement OCSP stapling support and typically do not enable it by default.

Metrics

References (66)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 26, 2016
Updated Aug 6, 2024
Reserved Jul 26, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 22, 2016