Infinite loop in BN_mod_sqrt() reachable when parsing certificates
Published Mar 15, 2022
7.5
HIGHCVSS 3.1
EPSS 73.19%
Description
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc).
Affected products
-
- Version Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc)StatusaffectedConstraints-
- Version Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m)StatusaffectedConstraints-
- Version Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1)StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
Configuration 2
- 9.0
- 10.0
- 11.0
Configuration 3
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- 34
- 36
Configuration 7
Configuration 8
- ≥ 10.2.0 · < 10.2.42
- ≥ 10.3.0 · < 10.3.33
- ≥ 10.4.0 · < 10.4.23
- ≥ 10.5.0 · < 10.5.14
- ≥ 10.6.0 · < 10.6.6
- ≥ 10.7.0 · < 10.7.2
Configuration 9
- ≥ 12.0.0 · ≤ 12.12.0
- ≥ 12.13.0 · < 12.22.11
- > 14.0.0 · ≤ 14.14.0
- ≥ 14.15.0 · < 14.19.1
- > 16.0.0 · ≤ 16.12.0
- ≥ 16.13.0 · < 16.14.2
- > 17.0.0 · < 17.7.2
No data.
JBoss Core Services for RHEL 8
jbcs-httpd24-apr-util-0:1.6.1-91.el8jbcs
Fixed · RHSA-2022:1389
JBoss Core Services for RHEL 8
jbcs-httpd24-curl-0:7.78.0-3.el8jbcs
Fixed · RHSA-2022:1389
JBoss Core Services for RHEL 8
jbcs-httpd24-httpd-0:2.4.37-80.el8jbcs
Fixed · RHSA-2022:1389
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_cluster-native-0:1.3.16-10.Final_redhat_2.el8jbcs
Fixed · RHSA-2022:1389
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_http2-0:1.15.7-22.el8jbcs
Fixed · RHSA-2022:1389
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_jk-0:1.2.48-29.redhat_1.el8jbcs
Fixed · RHSA-2022:1389
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_md-1:2.0.8-41.el8jbcs
Fixed · RHSA-2022:1389
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_security-0:2.9.2-68.GA.el8jbcs
Fixed · RHSA-2022:1389
JBoss Core Services for RHEL 8
jbcs-httpd24-nghttp2-0:1.39.2-41.el8jbcs
Fixed · RHSA-2022:1389
JBoss Core Services for RHEL 8
jbcs-httpd24-openssl-1:1.1.1g-11.el8jbcs
Fixed · RHSA-2022:1389
JBoss Core Services for RHEL 8
jbcs-httpd24-openssl-chil-0:1.0.0-11.el8jbcs
Fixed · RHSA-2022:1389
JBoss Core Services for RHEL 8
jbcs-httpd24-openssl-pkcs11-0:0.4.10-26.el8jbcs
Fixed · RHSA-2022:1389
JBoss Core Services on RHEL 7
jbcs-httpd24-apr-util-0:1.6.1-91.jbcs.el7
Fixed · RHSA-2022:1389
JBoss Core Services on RHEL 7
jbcs-httpd24-curl-0:7.78.0-3.jbcs.el7
Fixed · RHSA-2022:1389
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.37-80.jbcs.el7
Fixed · RHSA-2022:1389
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_cluster-native-0:1.3.16-10.Final_redhat_2.jbcs.el7
Fixed · RHSA-2022:1389
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_http2-0:1.15.7-22.jbcs.el7
Fixed · RHSA-2022:1389
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_jk-0:1.2.48-29.redhat_1.jbcs.el7
Fixed · RHSA-2022:1389
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_md-1:2.0.8-41.jbcs.el7
Fixed · RHSA-2022:1389
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_security-0:2.9.2-68.GA.jbcs.el7
Fixed · RHSA-2022:1389
JBoss Core Services on RHEL 7
jbcs-httpd24-nghttp2-0:1.39.2-41.jbcs.el7
Fixed · RHSA-2022:1389
JBoss Core Services on RHEL 7
jbcs-httpd24-openssl-1:1.1.1g-11.jbcs.el7
Fixed · RHSA-2022:1389
JBoss Core Services on RHEL 7
jbcs-httpd24-openssl-chil-0:1.0.0-11.jbcs.el7
Fixed · RHSA-2022:1389
JBoss Core Services on RHEL 7
jbcs-httpd24-openssl-pkcs11-0:0.4.10-26.jbcs.el7
Fixed · RHSA-2022:1389
Red Hat Enterprise Linux 6 Extended Lifecycle Support
openssl-0:1.0.1e-60.el6_10
Fixed · RHSA-2022:1073
Red Hat Enterprise Linux 7
openssl-1:1.0.2k-25.el7_9
Fixed · RHSA-2022:1066
Red Hat Enterprise Linux 7.3 Advanced Update Support
openssl-1:1.0.1e-62.el7_3
Fixed · RHSA-2022:1082
Red Hat Enterprise Linux 7.4 Advanced Update Support
openssl-1:1.0.2k-10.el7_4
Fixed · RHSA-2022:1076
Red Hat Enterprise Linux 7.6 Advanced Update Support
openssl-1:1.0.2k-18.el7_6
Fixed · RHSA-2022:1078
Red Hat Enterprise Linux 7.6 Telco Extended Update Support
openssl-1:1.0.2k-18.el7_6
Fixed · RHSA-2022:1078
Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions
openssl-1:1.0.2k-18.el7_6
Fixed · RHSA-2022:1078
Red Hat Enterprise Linux 7.7 Advanced Update Support
openssl-1:1.0.2k-21.el7_7
Fixed · RHSA-2022:1077
Red Hat Enterprise Linux 7.7 Telco Extended Update Support
openssl-1:1.0.2k-21.el7_7
Fixed · RHSA-2022:1077
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions
openssl-1:1.0.2k-21.el7_7
Fixed · RHSA-2022:1077
Red Hat Enterprise Linux 8
compat-openssl10-1:1.0.2o-4.el8_6
Fixed · RHSA-2022:5326
Red Hat Enterprise Linux 8
openssl-1:1.1.1k-6.el8_5
Fixed · RHSA-2022:1065
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
openssl-1:1.1.1c-5.el8_1.1
Fixed · RHSA-2022:1112
Red Hat Enterprise Linux 8.2 Extended Update Support
openssl-1:1.1.1c-19.el8_2
Fixed · RHSA-2022:1091
Red Hat Enterprise Linux 8.4 Extended Update Support
openssl-1:1.1.1g-16.el8_4
Fixed · RHSA-2022:1071
Red Hat Enterprise Linux 9
compat-openssl11-1:1.1.1k-4.el9_0
Fixed · RHSA-2022:4899
Red Hat JBoss Web Server 5
openssl
Fixed · RHSA-2022:1520
Red Hat JBoss Web Server 5.6 on RHEL 7
jws5-tomcat-0:9.0.50-5.redhat_00007.1.el7jws
Fixed · RHSA-2022:1519
Red Hat JBoss Web Server 5.6 on RHEL 7
jws5-tomcat-native-0:1.2.30-4.redhat_4.el7jws
Fixed · RHSA-2022:1519
Red Hat JBoss Web Server 5.6 on RHEL 8
jws5-tomcat-0:9.0.50-5.redhat_00007.1.el8jws
Fixed · RHSA-2022:1519
Red Hat JBoss Web Server 5.6 on RHEL 8
jws5-tomcat-native-0:1.2.30-4.redhat_4.el8jws
Fixed · RHSA-2022:1519
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.3.22-20220330.1.el7_9
Fixed · RHSA-2022:1263
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.5.0-202205291010_8.6
Fixed · RHSA-2022:4896
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/management-ingress-rhel8
Affected
Red Hat Enterprise Linux 6
openssl098e
Not affected
Red Hat Enterprise Linux 7
openssl098e
Not affected
Red Hat Enterprise Linux 7
ovmf
Not affected
Red Hat Enterprise Linux 8
edk2
Not affected
Red Hat Enterprise Linux 8
shim
Not affected
Red Hat Enterprise Linux 9
edk2
Not affected
Red Hat Enterprise Linux 9
openssl
Not affected
Red Hat Enterprise Linux 9
shim
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Out of support scope
Red Hat JBoss Web Server 3
openssl
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services for RHEL 8 | jbcs-httpd24-apr-util-0:1.6.1-91.el8jbcs | Fixed | RHSA-2022:1389 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-curl-0:7.78.0-3.el8jbcs | Fixed | RHSA-2022:1389 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-httpd-0:2.4.37-80.el8jbcs | Fixed | RHSA-2022:1389 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_cluster-native-0:1.3.16-10.Final_redhat_2.el8jbcs | Fixed | RHSA-2022:1389 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_http2-0:1.15.7-22.el8jbcs | Fixed | RHSA-2022:1389 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_jk-0:1.2.48-29.redhat_1.el8jbcs | Fixed | RHSA-2022:1389 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_md-1:2.0.8-41.el8jbcs | Fixed | RHSA-2022:1389 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_security-0:2.9.2-68.GA.el8jbcs | Fixed | RHSA-2022:1389 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-nghttp2-0:1.39.2-41.el8jbcs | Fixed | RHSA-2022:1389 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-openssl-1:1.1.1g-11.el8jbcs | Fixed | RHSA-2022:1389 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-openssl-chil-0:1.0.0-11.el8jbcs | Fixed | RHSA-2022:1389 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-openssl-pkcs11-0:0.4.10-26.el8jbcs | Fixed | RHSA-2022:1389 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-apr-util-0:1.6.1-91.jbcs.el7 | Fixed | RHSA-2022:1389 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-curl-0:7.78.0-3.jbcs.el7 | Fixed | RHSA-2022:1389 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.37-80.jbcs.el7 | Fixed | RHSA-2022:1389 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_cluster-native-0:1.3.16-10.Final_redhat_2.jbcs.el7 | Fixed | RHSA-2022:1389 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_http2-0:1.15.7-22.jbcs.el7 | Fixed | RHSA-2022:1389 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_jk-0:1.2.48-29.redhat_1.jbcs.el7 | Fixed | RHSA-2022:1389 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_md-1:2.0.8-41.jbcs.el7 | Fixed | RHSA-2022:1389 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_security-0:2.9.2-68.GA.jbcs.el7 | Fixed | RHSA-2022:1389 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-nghttp2-0:1.39.2-41.jbcs.el7 | Fixed | RHSA-2022:1389 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-openssl-1:1.1.1g-11.jbcs.el7 | Fixed | RHSA-2022:1389 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-openssl-chil-0:1.0.0-11.jbcs.el7 | Fixed | RHSA-2022:1389 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-openssl-pkcs11-0:0.4.10-26.jbcs.el7 | Fixed | RHSA-2022:1389 |
| Red Hat Enterprise Linux 6 Extended Lifecycle Support | openssl-0:1.0.1e-60.el6_10 | Fixed | RHSA-2022:1073 |
| Red Hat Enterprise Linux 7 | openssl-1:1.0.2k-25.el7_9 | Fixed | RHSA-2022:1066 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | openssl-1:1.0.1e-62.el7_3 | Fixed | RHSA-2022:1082 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | openssl-1:1.0.2k-10.el7_4 | Fixed | RHSA-2022:1076 |
| Red Hat Enterprise Linux 7.6 Advanced Update Support | openssl-1:1.0.2k-18.el7_6 | Fixed | RHSA-2022:1078 |
| Red Hat Enterprise Linux 7.6 Telco Extended Update Support | openssl-1:1.0.2k-18.el7_6 | Fixed | RHSA-2022:1078 |
| Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions | openssl-1:1.0.2k-18.el7_6 | Fixed | RHSA-2022:1078 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | openssl-1:1.0.2k-21.el7_7 | Fixed | RHSA-2022:1077 |
| Red Hat Enterprise Linux 7.7 Telco Extended Update Support | openssl-1:1.0.2k-21.el7_7 | Fixed | RHSA-2022:1077 |
| Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | openssl-1:1.0.2k-21.el7_7 | Fixed | RHSA-2022:1077 |
| Red Hat Enterprise Linux 8 | compat-openssl10-1:1.0.2o-4.el8_6 | Fixed | RHSA-2022:5326 |
| Red Hat Enterprise Linux 8 | openssl-1:1.1.1k-6.el8_5 | Fixed | RHSA-2022:1065 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | openssl-1:1.1.1c-5.el8_1.1 | Fixed | RHSA-2022:1112 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | openssl-1:1.1.1c-19.el8_2 | Fixed | RHSA-2022:1091 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | openssl-1:1.1.1g-16.el8_4 | Fixed | RHSA-2022:1071 |
| Red Hat Enterprise Linux 9 | compat-openssl11-1:1.1.1k-4.el9_0 | Fixed | RHSA-2022:4899 |
| Red Hat JBoss Web Server 5 | openssl | Fixed | RHSA-2022:1520 |
| Red Hat JBoss Web Server 5.6 on RHEL 7 | jws5-tomcat-0:9.0.50-5.redhat_00007.1.el7jws | Fixed | RHSA-2022:1519 |
| Red Hat JBoss Web Server 5.6 on RHEL 7 | jws5-tomcat-native-0:1.2.30-4.redhat_4.el7jws | Fixed | RHSA-2022:1519 |
| Red Hat JBoss Web Server 5.6 on RHEL 8 | jws5-tomcat-0:9.0.50-5.redhat_00007.1.el8jws | Fixed | RHSA-2022:1519 |
| Red Hat JBoss Web Server 5.6 on RHEL 8 | jws5-tomcat-native-0:1.2.30-4.redhat_4.el8jws | Fixed | RHSA-2022:1519 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.3.22-20220330.1.el7_9 | Fixed | RHSA-2022:1263 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.5.0-202205291010_8.6 | Fixed | RHSA-2022:4896 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/management-ingress-rhel8 | Affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ovmf | Not affected | n/a |
| Red Hat Enterprise Linux 8 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 9 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 9 | shim | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Out of support scope | n/a |
| Red Hat JBoss Web Server 3 | openssl | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
While Red Hat initially stated not to be directly affected by this flaw, after further investigation we found that the versions of OpenSSL as shipped in Red Hat Enterprise Linux 6, 7, and 8 are vulnerable to a denial of service attack through malicious Elliptic Curve parameters. During processing of the parameters OpenSSL will call BN_mod_sqrt() with invalid arguments, causing the process to enter an infinite loop. The invalid EC parameters can be provided to OpenSSL through X.509 certificates (used in TLS connections), through public and private keys, through certificate signing requests and other places where applications process Elliptic Curve parameters. The flaw has been rated as having a security impact of Important. A future update will address this issue in Red Hat Enterprise Linux 6, 7 and 8.
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
References (46)
- http://packetstormsecurity.com/files/167344/OpenSSL-1.0.2-1.1.1-3.0-BN_mod_sqrt-Infinite-Loop.html Third Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2022/May/33 mailing-listMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/May/35 mailing-listMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/May/38 mailing-listMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-0778 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2062202 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-019200.html
- https://cert-portal.siemens.com/productcert/html/ssa-028723.html
- https://cert-portal.siemens.com/productcert/html/ssa-108696.html
- https://cert-portal.siemens.com/productcert/html/ssa-398330.html
- https://cert-portal.siemens.com/productcert/html/ssa-712929.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-712929.pdf Third Party Advisory
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3118eb64934499d93db3230748a452351d1d9a65
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=380085481c64de749a6dd25cdf0bcf4360b30f83
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a466912611aa6cbdf550cd10601390e587451246
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=3118eb64934499d93db3230748a452351d1d9a65
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=380085481c64de749a6dd25cdf0bcf4360b30f83
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=a466912611aa6cbdf550cd10601390e587451246
- https://github.com/advisories/GHSA-x3mh-jvjw-3xwx Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00023.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00024.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GDB3GQVJPXJE7X5C5JN6JAA4XUDWD6E6 vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6K3PR542DXWLEFFMFIDMME4CWMHJRMG vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GDB3GQVJPXJE7X5C5JN6JAA4XUDWD6E6
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W6K3PR542DXWLEFFMFIDMME4CWMHJRMG
- https://nvd.nist.gov/vuln/detail/CVE-2022-0778
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0002 Third Party Advisory
- https://rustsec.org/advisories/RUSTSEC-2022-0014.html
- https://security.gentoo.org/glsa/202210-02 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220321-0002 Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220429-0005 Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240621-0006
- https://support.apple.com/kb/HT213255 Third Party Advisory
- https://support.apple.com/kb/HT213256 Third Party Advisory
- https://support.apple.com/kb/HT213257 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-0778
- https://www.debian.org/security/2022/dsa-5103 vendor-advisoryThird Party Advisory
- https://www.openssl.org/news/secadv/20220315.txt Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html Third Party Advisory
- https://www.tenable.com/security/tns-2022-06 Third Party Advisory
- https://www.tenable.com/security/tns-2022-07 Third Party Advisory
- https://www.tenable.com/security/tns-2022-08 Third Party Advisory
- https://www.tenable.com/security/tns-2022-09 Third Party Advisory
Change history (0)
No recorded changes yet.