Back

CRITICAL

RSA implementation bug in AVX512IFMA instructions

Published Jul 1, 2022

Description

The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation. SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86_64 architecture are affected by this issue.

Affected products

Remediation

Red Hat statement

This vulnerability was introduced in OpenSSL 3.0.4 via upstream commit 10d8a10. The versions of OpenSSL as shipped with Red Hat Enterprise Linux are not affected by this flaw, as they did not backport the upstream commit that introduced this issue.

Red Hat mitigation

Disabling the AVX512IFMA instruction set extension can effectively mitigate this flaw: ``` export OPENSSL_ia32cap=:~0x200000 ```

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner openssl
Published Jul 1, 2022
Updated Sep 17, 2024
Reserved Jun 30, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 22, 2022
GHSA-735F-PG76-FXC4