AES OCB fails to encrypt some bytes
Published Jul 5, 2022
7.5
HIGHCVSS 3.1
EPSS 4.90%
Description
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).
Affected products
-
- Version Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p)StatusaffectedConstraints-
- Version Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4)StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
Configuration 2
- 35
- 36
Configuration 3
- n/a
- n/a
Configuration 4
- n/a
Running on/with
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
Configuration 10
- 10.0
- 11.0
-
- Version 10.0StatusaffectedConstraints-
- Version 11.0StatusaffectedConstraints-
- Version
-
- Version 35StatusaffectedConstraints-
- Version 36StatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints-
- Version
-
- Version h300sStatusaffectedConstraints-
- Version h410cStatusaffectedConstraints-
- Version h410sStatusaffectedConstraints-
- Version h500sStatusaffectedConstraints-
- Version h700sStatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints-
- Version
-
- Version 1.1.1StatusaffectedConstraints<1.1.1q
- Version 3.0.0StatusaffectedConstraints<3.0.5
- Version
-
- Version 0StatusaffectedConstraints<1.0_sp2_update_1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Debian | Debian Linux | n/a |
| ||||||||||||||||||
| Fedora Project | Fedora | n/a |
| ||||||||||||||||||
| NetApp | Active IQ Unified Manager for Vmware Vsphere | n/a |
| ||||||||||||||||||
| NetApp | Brocade Fabric Operating System Firmware | n/a |
| ||||||||||||||||||
| NetApp | Hci Baseboard Management Controller | n/a |
| ||||||||||||||||||
| NetApp | Oncommand Insight | n/a |
| ||||||||||||||||||
| NetApp | Ontap Antivirus Connector | n/a |
| ||||||||||||||||||
| NetApp | Ontap Select Deploy Administration Utility | n/a |
| ||||||||||||||||||
| NetApp | Smi-S Provider | n/a |
| ||||||||||||||||||
| NetApp | Snapcenter | n/a |
| ||||||||||||||||||
| OpenSSL | OpenSSL | n/a |
| ||||||||||||||||||
| Siemens | Sinec Ins | n/a |
|
Red Hat Enterprise Linux 8
openssl-1:1.1.1k-7.el8_6
Fixed · RHSA-2022:5818
Red Hat Enterprise Linux 9
openssl-1:3.0.1-41.el9_0
Fixed · RHSA-2022:6224
Red Hat Enterprise Linux 9
openssl-1:3.0.1-41.el9_0
Fixed · RHSA-2022:6224
Red Hat Enterprise Linux 6
openssl
Not affected
Red Hat Enterprise Linux 6
openssl098e
Not affected
Red Hat Enterprise Linux 7
openssl
Not affected
Red Hat Enterprise Linux 7
openssl098e
Not affected
Red Hat Enterprise Linux 7
ovmf
Out of support scope
Red Hat Enterprise Linux 8
compat-openssl10
Not affected
Red Hat Enterprise Linux 8
edk2
Not affected
Red Hat Enterprise Linux 8
shim
Not affected
Red Hat Enterprise Linux 9
compat-openssl11
Will not fix
Red Hat Enterprise Linux 9
edk2
Not affected
Red Hat Enterprise Linux 9
shim
Not affected
Red Hat JBoss Core Services
openssl
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Out of support scope
Red Hat JBoss Web Server 3
openssl
Out of support scope
Red Hat JBoss Web Server 5
openssl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | openssl-1:1.1.1k-7.el8_6 | Fixed | RHSA-2022:5818 |
| Red Hat Enterprise Linux 9 | openssl-1:3.0.1-41.el9_0 | Fixed | RHSA-2022:6224 |
| Red Hat Enterprise Linux 9 | openssl-1:3.0.1-41.el9_0 | Fixed | RHSA-2022:6224 |
| Red Hat Enterprise Linux 6 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ovmf | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | compat-openssl10 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 9 | compat-openssl11 | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | shim | Not affected | n/a |
| Red Hat JBoss Core Services | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Out of support scope | n/a |
| Red Hat JBoss Web Server 3 | openssl | Out of support scope | n/a |
| Red Hat JBoss Web Server 5 | openssl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7 ship OpenSSL 1.0 which does not contain the incorrect assembly code (introduced upstream with commit bd30091). Similarly, the versions of `shim` as shipped with Red Hat Enterprise Linux 8 and 9 are not affected by this issue as they bundle openssl-1.0.2j.
References (24)
- https://access.redhat.com/security/cve/CVE-2022-2097 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2104905 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf Third Party Advisory
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=919925673d6c9cfed3c1085497f5dfbbed5fc431
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a98f339ddd7e8f487d6e0088d4a9a42324885a93
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=919925673d6c9cfed3c1085497f5dfbbed5fc431
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=a98f339ddd7e8f487d6e0088d4a9a42324885a93
- https://github.com/advisories/GHSA-3wx7-46ch-7rq2 Advisory
- https://lists.debian.org/debian-lts-announce/2023/02/msg00019.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7 vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA
- https://nvd.nist.gov/vuln/detail/CVE-2022-2097
- https://rustsec.org/advisories/RUSTSEC-2022-0032.html
- https://security.gentoo.org/glsa/202210-02 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220715-0011 Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230420-0008
- https://security.netapp.com/advisory/ntap-20240621-0006
- https://www.cve.org/CVERecord?id=CVE-2022-2097
- https://www.debian.org/security/2023/dsa-5343 vendor-advisoryThird Party Advisory
- https://www.openssl.org/news/secadv/20220705.txt Vendor Advisory
Change history (0)
No recorded changes yet.