SSL/TLS: Malformed plain-text ALERT packets could cause remote DoS
Published Nov 13, 2017
7.5
HIGHCVSS 3.1
EPSS 39.66%
Description
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
Affected products
-
- Version 1.0.2 through 1.0.2hStatusaffectedConstraints-
- Version 1.1.0StatusaffectedConstraints-
- Version All 0.9.8StatusaffectedConstraints-
- Version All 1.0.1StatusaffectedConstraints-
- Version
Configuration 1
Configuration 2
- 8.0
Configuration 3
- 6.0
- 7.0
- 6.0
- 7.0
- 7.3
- 7.4
- 7.6
- 7.3
- 7.4
- 7.5
- 7.6
- 7.3
- 7.6
- 6.0
- 7.0
Configuration 4
- 6.0.0
- 6.4.0
Running on/with
- 6.0
- 7.0
Configuration 5
- n/a
Configuration 6
- n/a
- n/a
- n/a
- ≥ 11.0 · ≤ 11.40
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 7
- ≤ 6.1.17
- ≥ 7.0.0 · ≤ 7.0.15
- ≥ 7.1.0 · ≤ 7.1.10
Configuration 8
- 11.1.2.3.0
- 13.3.0.1
- 12.1.1
- 7.3.4
- 7.4.0
- 11.2.0.4
- 12.1.0.2
- 12.2.0.1
- 18c
- 19c
- 12.3.3
- 12.4.0
- 12.3.2.1.0
- 9.2
- 8.56
- 8.57
- 8.58
- 15.0.3
- 16.0.3
- < 18.1.4.1.0
- 10.3.6.0.0
- 12.1.3.0.0
- 12.2.1.3.0
- 12.2.1.4.0
Configuration 9
- < xcp2361
- ≥ xcp3000 · < xcp3070
Configuration 10
- < xcp2361
- ≥ xcp3000 · < xcp3070
Configuration 11
- < xcp2361
- ≥ xcp3000 · < xcp3070
Configuration 12
- < xcp2361
- ≥ xcp3000 · < xcp3070
Configuration 13
- < xcp2361
- ≥ xcp3000 · < xcp3070
Configuration 14
- < xcp2361
- ≥ xcp3000 · < xcp3070
No data.
JBoss Core Services on RHEL 6
jbcs-httpd24-httpd-0:2.4.23-120.jbcs.el6
Fixed · RHSA-2017:1414
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_security-0:2.9.1-19.GA.jbcs.el6
Fixed · RHSA-2017:1414
JBoss Core Services on RHEL 6
jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el6
Fixed · RHSA-2017:1414
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.23-120.jbcs.el7
Fixed · RHSA-2017:1413
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_security-0:2.9.1-19.GA.jbcs.el7
Fixed · RHSA-2017:1413
JBoss Core Services on RHEL 7
jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el7
Fixed · RHSA-2017:1413
Red Hat Enterprise Linux 6
gnutls-0:2.12.23-21.el6
Fixed · RHSA-2017:0574
Red Hat Enterprise Linux 6
openssl-0:1.0.1e-48.el6_8.4
Fixed · RHSA-2017:0286
Red Hat Enterprise Linux 7
openssl-1:1.0.1e-60.el7_3.1
Fixed · RHSA-2017:0286
Red Hat JBoss Core Services
n/a
Fixed · RHSA-2017:1415
Red Hat JBoss Enterprise Application Platform 6.4
openssl
Fixed · RHSA-2017:1659
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6
jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el6
Fixed · RHSA-2017:1658
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7
jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el7
Fixed · RHSA-2017:1658
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el6
Fixed · RHSA-2017:2493
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
tomcat6-0:6.0.41-17_patch_04.ep6.el6
Fixed · RHSA-2017:2493
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
tomcat7-0:7.0.54-25_patch_05.ep6.el6
Fixed · RHSA-2017:2493
Red Hat JBoss Enterprise Web Server 2 for RHEL 7
jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el7
Fixed · RHSA-2017:2493
Red Hat JBoss Enterprise Web Server 2 for RHEL 7
tomcat6-0:6.0.41-17_patch_04.ep6.el7
Fixed · RHSA-2017:2493
Red Hat JBoss Enterprise Web Server 2 for RHEL 7
tomcat7-0:7.0.54-25_patch_05.ep6.el7
Fixed · RHSA-2017:2493
Red Hat JBoss Web Server 2.1
openssl
Fixed · RHSA-2017:2494
Red Hat JBoss Web Server 3 for RHEL 6
log4j-eap6-0:1.2.16-12.redhat_3.1.ep6.el6
Fixed · RHSA-2017:1801
Red Hat JBoss Web Server 3 for RHEL 6
tomcat-native-0:1.2.8-10.redhat_10.ep7.el6
Fixed · RHSA-2017:1801
Red Hat JBoss Web Server 3 for RHEL 6
tomcat7-0:7.0.70-22.ep7.el6
Fixed · RHSA-2017:1801
Red Hat JBoss Web Server 3 for RHEL 6
tomcat8-0:8.0.36-24.ep7.el6
Fixed · RHSA-2017:1801
Red Hat JBoss Web Server 3 for RHEL 7
log4j-eap6-0:1.2.16-12.redhat_3.1.ep6.el7
Fixed · RHSA-2017:1801
Red Hat JBoss Web Server 3 for RHEL 7
tomcat-native-0:1.2.8-10.redhat_10.ep7.el7
Fixed · RHSA-2017:1801
Red Hat JBoss Web Server 3 for RHEL 7
tomcat7-0:7.0.70-22.ep7.el7
Fixed · RHSA-2017:1801
Red Hat JBoss Web Server 3 for RHEL 7
tomcat8-0:8.0.36-24.ep7.el7
Fixed · RHSA-2017:1801
Red Hat JBoss Web Server 3.1
n/a
Fixed · RHSA-2017:1802
Red Hat Enterprise Linux 5
gnutls
Will not fix
Red Hat Enterprise Linux 5
nss
Not affected
Red Hat Enterprise Linux 5
openssl
Will not fix
Red Hat Enterprise Linux 5
openssl097a
Will not fix
Red Hat Enterprise Linux 6
nss
Not affected
Red Hat Enterprise Linux 6
openssl098e
Will not fix
Red Hat Enterprise Linux 7
gnutls
Will not fix
Red Hat Enterprise Linux 7
nss
Not affected
Red Hat Enterprise Linux 7
openssl098e
Will not fix
Red Hat JBoss Enterprise Web Server 1
openssl
Will not fix
Red Hat JBoss Enterprise Web Server 3
openssl
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd-0:2.4.23-120.jbcs.el6 | Fixed | RHSA-2017:1414 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_security-0:2.9.1-19.GA.jbcs.el6 | Fixed | RHSA-2017:1414 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el6 | Fixed | RHSA-2017:1414 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.23-120.jbcs.el7 | Fixed | RHSA-2017:1413 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_security-0:2.9.1-19.GA.jbcs.el7 | Fixed | RHSA-2017:1413 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el7 | Fixed | RHSA-2017:1413 |
| Red Hat Enterprise Linux 6 | gnutls-0:2.12.23-21.el6 | Fixed | RHSA-2017:0574 |
| Red Hat Enterprise Linux 6 | openssl-0:1.0.1e-48.el6_8.4 | Fixed | RHSA-2017:0286 |
| Red Hat Enterprise Linux 7 | openssl-1:1.0.1e-60.el7_3.1 | Fixed | RHSA-2017:0286 |
| Red Hat JBoss Core Services | n/a | Fixed | RHSA-2017:1415 |
| Red Hat JBoss Enterprise Application Platform 6.4 | openssl | Fixed | RHSA-2017:1659 |
| Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 | jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el6 | Fixed | RHSA-2017:1658 |
| Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 | jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el7 | Fixed | RHSA-2017:1658 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el6 | Fixed | RHSA-2017:2493 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | tomcat6-0:6.0.41-17_patch_04.ep6.el6 | Fixed | RHSA-2017:2493 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | tomcat7-0:7.0.54-25_patch_05.ep6.el6 | Fixed | RHSA-2017:2493 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 7 | jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el7 | Fixed | RHSA-2017:2493 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 7 | tomcat6-0:6.0.41-17_patch_04.ep6.el7 | Fixed | RHSA-2017:2493 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 7 | tomcat7-0:7.0.54-25_patch_05.ep6.el7 | Fixed | RHSA-2017:2493 |
| Red Hat JBoss Web Server 2.1 | openssl | Fixed | RHSA-2017:2494 |
| Red Hat JBoss Web Server 3 for RHEL 6 | log4j-eap6-0:1.2.16-12.redhat_3.1.ep6.el6 | Fixed | RHSA-2017:1801 |
| Red Hat JBoss Web Server 3 for RHEL 6 | tomcat-native-0:1.2.8-10.redhat_10.ep7.el6 | Fixed | RHSA-2017:1801 |
| Red Hat JBoss Web Server 3 for RHEL 6 | tomcat7-0:7.0.70-22.ep7.el6 | Fixed | RHSA-2017:1801 |
| Red Hat JBoss Web Server 3 for RHEL 6 | tomcat8-0:8.0.36-24.ep7.el6 | Fixed | RHSA-2017:1801 |
| Red Hat JBoss Web Server 3 for RHEL 7 | log4j-eap6-0:1.2.16-12.redhat_3.1.ep6.el7 | Fixed | RHSA-2017:1801 |
| Red Hat JBoss Web Server 3 for RHEL 7 | tomcat-native-0:1.2.8-10.redhat_10.ep7.el7 | Fixed | RHSA-2017:1801 |
| Red Hat JBoss Web Server 3 for RHEL 7 | tomcat7-0:7.0.70-22.ep7.el7 | Fixed | RHSA-2017:1801 |
| Red Hat JBoss Web Server 3 for RHEL 7 | tomcat8-0:8.0.36-24.ep7.el7 | Fixed | RHSA-2017:1801 |
| Red Hat JBoss Web Server 3.1 | n/a | Fixed | RHSA-2017:1802 |
| Red Hat Enterprise Linux 5 | gnutls | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | nss | Not affected | n/a |
| Red Hat Enterprise Linux 5 | openssl | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | nss | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | gnutls | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | nss | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Will not fix | n/a |
| Red Hat JBoss Enterprise Web Server 1 | openssl | Will not fix | n/a |
| Red Hat JBoss Enterprise Web Server 3 | openssl | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw affects applications that are compiled against OpenSSL or GnuTLS and do not allocate an extra thread for processing ClientHello messages. Nginx is affected by this issue; Apache httpd is not affected by this issue. This issue has been rated as having a security impact of Moderate. It requires an attacker to send a very large amount of SSL ALERT messages to the host network connection. This issue can also be mitigated by configuring firewalls to limit the number of connections per IP address, or use deep packet inspection to reject these type of alert packets. A future update may address this issue.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (25 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 39.66% (0.39657) | 98.58th | v5 (v2026.06.15) |
| Jun 15, 2026 | 39.66% (0.39657) | 98.43th | v5 (v2026.06.15) |
| Nov 12, 2025 | 71.13% (0.71130) | 98.64th | v4 (v2025.03.14) |
| Sep 20, 2025 | 68.60% (0.68604) | 98.58th | v4 (v2025.03.14) |
| Sep 11, 2025 | 71.83% (0.71829) | 98.69th | v4 (v2025.03.14) |
| Jul 12, 2025 | 70.01% (0.70009) | 98.58th | v4 (v2025.03.14) |
| Jul 7, 2025 | 71.36% (0.71356) | 98.63th | v4 (v2025.03.14) |
| Mar 30, 2025 | 69.23% (0.69235) | 98.53th | v4 (v2025.03.14) |
| Mar 29, 2025 | 72.53% (0.72528) | 98.37th | v4 (v2025.03.14) |
| Mar 28, 2025 | 69.23% (0.69235) | 98.53th | v4 (v2025.03.14) |
| Mar 17, 2025 | 71.65% (0.71649) | 98.64th | v4 (v2025.03.14) |
| Dec 17, 2024 | 28.39% (0.28387) | 96.84th | v3 (v2023.03.01) |
| Dec 12, 2024 | 52.11% (0.52111) | 97.70th | v3 (v2023.03.01) |
| Oct 16, 2024 | 52.59% (0.52592) | 97.65th | v3 (v2023.03.01) |
| Sep 3, 2024 | 26.97% (0.26973) | 96.85th | v3 (v2023.03.01) |
| Aug 13, 2024 | 20.25% (0.20249) | 96.43th | v3 (v2023.03.01) |
| Aug 10, 2024 | 2.83% (0.02826) | 90.82th | v3 (v2023.03.01) |
| Feb 17, 2024 | 20.25% (0.20249) | 96.20th | v3 (v2023.03.01) |
| Jan 27, 2024 | 24.67% (0.24668) | 96.22th | v3 (v2023.03.01) |
| Jun 9, 2023 | 57.73% (0.57732) | 97.19th | v3 (v2023.03.01) |
| May 16, 2023 | 62.68% (0.62678) | 97.29th | v3 (v2023.03.01) |
| Apr 6, 2023 | 66.49% (0.66493) | 97.35th | v3 (v2023.03.01) |
| Mar 7, 2023 | 74.96% (0.74957) | 97.56th | v3 (v2023.03.01) |
| Mar 6, 2023 | 49.93% (0.49928) | 98.72th | v2 (v2022.01.01) |
| Feb 4, 2022 | 49.93% (0.49928) | 98.29th | v2 (v2022.01.01) |
References (33)
- http://rhn.redhat.com/errata/RHSA-2017-0286.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0574.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-1415.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-1659.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://seclists.org/oss-sec/2016/q4/224 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://security.360.cn/cve/CVE-2016-8610
- http://www.securityfocus.com/bid/93841 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037084 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1413 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1414 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1658 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1801 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1802 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2493 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2494 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2016-8610 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1384743 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8610 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=af58be768ebb690f78530f796e92b8ae5c9a4401 x_refsource_CONFIRMBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2016-8610
- https://security.360.cn/cve/CVE-2016-8610/ x_refsource_MISCThird Party Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-16:35.openssl.asc vendor-advisoryx_refsource_FREEBSDThird Party Advisory
- https://security.netapp.com/advisory/ntap-20171130-0001/ x_refsource_CONFIRMThird Party Advisory
- https://security.paloaltonetworks.com/CVE-2016-8610 x_refsource_CONFIRMThird Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03897en_us x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2016-8610
- https://www.debian.org/security/2017/dsa-3773 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.