RSA implementation bug in AVX512IFMA instructions
Published Jul 1, 2022
9.8
CRITICALCVSS 3.1
EPSS 45.67%
Description
The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation. SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86_64 architecture are affected by this issue.
Affected products
-
- Version Affects OpenSSL 3.0.4StatusaffectedConstraints-
- Version
Configuration 2
- n/a
Configuration 3
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
No data.
Red Hat Enterprise Linux 6
openssl
Not affected
Red Hat Enterprise Linux 7
openssl
Not affected
Red Hat Enterprise Linux 7
ovmf
Not affected
Red Hat Enterprise Linux 8
compat-openssl10
Not affected
Red Hat Enterprise Linux 8
edk2
Not affected
Red Hat Enterprise Linux 8
openssl
Not affected
Red Hat Enterprise Linux 8
shim
Not affected
Red Hat Enterprise Linux 9
compat-openssl11
Not affected
Red Hat Enterprise Linux 9
edk2
Not affected
Red Hat Enterprise Linux 9
openssl
Not affected
Red Hat Enterprise Linux 9
shim
Not affected
Red Hat JBoss Core Services
jbcs-httpd24-openssl
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Not affected
Red Hat JBoss Web Server 3
openssl
Not affected
Red Hat JBoss Web Server 5
openssl
Not affected
Red Hat Virtualization 4
redhat-virtualization-host
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ovmf | Not affected | n/a |
| Red Hat Enterprise Linux 8 | compat-openssl10 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 9 | compat-openssl11 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 9 | shim | Not affected | n/a |
| Red Hat JBoss Core Services | jbcs-httpd24-openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Not affected | n/a |
| Red Hat JBoss Web Server 3 | openssl | Not affected | n/a |
| Red Hat JBoss Web Server 5 | openssl | Not affected | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability was introduced in OpenSSL 3.0.4 via upstream commit 10d8a10. The versions of OpenSSL as shipped with Red Hat Enterprise Linux are not affected by this flaw, as they did not backport the upstream commit that introduced this issue.
Red Hat mitigation
Disabling the AVX512IFMA instruction set extension can effectively mitigate this flaw: ``` export OPENSSL_ia32cap=:~0x200000 ```
References (12)
- https://access.redhat.com/security/cve/CVE-2022-2274 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2102943 Issue Tracking
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=4d8a88c134df634ba610ff8db1eb8478ac5fd345 x_refsource_CONFIRM
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=4d8a88c134df634ba610ff8db1eb8478ac5fd345
- https://github.com/advisories/GHSA-735f-pg76-fxc4 Advisory
- https://github.com/openssl/openssl/issues/18625 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://guidovranken.com/2022/06/27/notes-on-openssl-remote-memory-corruption/
- https://nvd.nist.gov/vuln/detail/CVE-2022-2274
- https://rustsec.org/advisories/RUSTSEC-2022-0033.html
- https://security.netapp.com/advisory/ntap-20220715-0010/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-2274
- https://www.openssl.org/news/secadv/20220705.txt x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2274 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2102943 | Issue Tracking | |
| https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=4d8a88c134df634ba610ff8db1eb8478ac5fd345 | x_refsource_CONFIRM | |
| https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=4d8a88c134df634ba610ff8db1eb8478ac5fd345 | ||
| https://github.com/advisories/GHSA-735f-pg76-fxc4 | Advisory | |
| https://github.com/openssl/openssl/issues/18625 | x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory | |
| https://guidovranken.com/2022/06/27/notes-on-openssl-remote-memory-corruption/ | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-2274 | ||
| https://rustsec.org/advisories/RUSTSEC-2022-0033.html | ||
| https://security.netapp.com/advisory/ntap-20220715-0010/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-2274 | ||
| https://www.openssl.org/news/secadv/20220705.txt | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.