X.509 Email Address 4-byte Buffer Overflow
Published Nov 1, 2022
9.8
CRITICALCVSS 3.1
EPSS 90.77%
Description
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address to overflow four attacker-controlled bytes on the stack. This buffer overflow could result in a crash (causing a denial of service) or potentially remote code execution. Many platforms implement stack overflow protections which would mitigate against the risk of remote code execution. The risk may be further mitigated based on stack layout for any given platform/compiler. Pre-announcements of CVE-2022-3602 described this issue as CRITICAL. Further analysis based on some of the mitigating factors described above have led this to be downgraded to HIGH. Users are still encouraged to upgrade to a new version as soon as possible. In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects. Fixed in OpenSSL 3.0.7 (Affected 3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6).
Affected products
-
- Version Fixed in OpenSSL 3.0.7 (Affected 3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6)StatusaffectedConstraints-
- Version
Configuration 2
- 36
- 37
Configuration 3
- n/a
Configuration 4
- 26
- 27
No data.
Red Hat Enterprise Linux 9
openssl-1:3.0.1-43.el9_0
Fixed · RHSA-2022:7288
Red Hat Enterprise Linux 9
openssl-1:3.0.1-43.el9_0
Fixed · RHSA-2022:7288
Red Hat Enterprise Linux 9
rhel9/openssl:9.0-25
Fixed · RHSA-2022:7384
Red Hat Enterprise Linux 9
ubi9/openssl:9.0-25
Fixed · RHSA-2022:7384
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/management-ingress-rhel8
Not affected
Red Hat Enterprise Linux 6
openssl
Not affected
Red Hat Enterprise Linux 6
openssl098e
Not affected
Red Hat Enterprise Linux 7
openssl
Not affected
Red Hat Enterprise Linux 7
openssl098e
Not affected
Red Hat Enterprise Linux 7
ovmf
Not affected
Red Hat Enterprise Linux 8
compat-openssl10
Not affected
Red Hat Enterprise Linux 8
edk2
Not affected
Red Hat Enterprise Linux 8
openssl
Not affected
Red Hat Enterprise Linux 8
shim
Not affected
Red Hat Enterprise Linux 9
compat-openssl11
Not affected
Red Hat Enterprise Linux 9
edk2
Not affected
Red Hat Enterprise Linux 9
shim
Not affected
Red Hat JBoss Core Services
jbcs-httpd24-openssl
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Not affected
Red Hat JBoss Web Server 3
openssl
Not affected
Red Hat JBoss Web Server 5
openssl
Not affected
Red Hat Virtualization 4
redhat-virtualization-host
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | openssl-1:3.0.1-43.el9_0 | Fixed | RHSA-2022:7288 |
| Red Hat Enterprise Linux 9 | openssl-1:3.0.1-43.el9_0 | Fixed | RHSA-2022:7288 |
| Red Hat Enterprise Linux 9 | rhel9/openssl:9.0-25 | Fixed | RHSA-2022:7384 |
| Red Hat Enterprise Linux 9 | ubi9/openssl:9.0-25 | Fixed | RHSA-2022:7384 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/management-ingress-rhel8 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ovmf | Not affected | n/a |
| Red Hat Enterprise Linux 8 | compat-openssl10 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 9 | compat-openssl11 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | shim | Not affected | n/a |
| Red Hat JBoss Core Services | jbcs-httpd24-openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Not affected | n/a |
| Red Hat JBoss Web Server 3 | openssl | Not affected | n/a |
| Red Hat JBoss Web Server 5 | openssl | Not affected | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
As per upstream, the most common situation where this can be triggered is when a server requests client authentication after a malicious client connects. A client connecting to a malicious server is also believed to be vulnerable in the same manner. Only OpenSSL versions 3.0.0 to 3.0.6 are vulnerable to this attack. The OpenSSL binaries in Red Hat Enterprise Linux 9 are compiled with Stack Smashing Protection. Also during the build process, the compiler rearranges the variables in a way that the buffer overflow is only able to overwrite the stack canaries, limiting the maximum impact of this flaw to denial of service. Remote code execution may not be possible in such cases. Red Hat OpenStack Platform 17 does not ship OpenSSL and is not directly affected by the flaw. However, container images which product ship are of RHEL 9 which were affected. RHOSP have fixed this by respining container images through the following errata: https://access.redhat.com/errata/RHBA-2022:7429
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (GHSA) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Apr 23, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (75 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 90.77% (0.90770) | 99.80th | v5 (v2026.06.15) |
| Jun 15, 2026 | 89.80% (0.89804) | 99.77th | v5 (v2026.06.15) |
| May 5, 2026 | 83.51% (0.83506) | 99.29th | v4 (v2025.03.14) |
| Apr 27, 2026 | 84.62% (0.84616) | 99.34th | v4 (v2025.03.14) |
| Apr 23, 2026 | 83.22% (0.83219) | 99.27th | v4 (v2025.03.14) |
| Apr 21, 2026 | 84.36% (0.84357) | 99.32th | v4 (v2025.03.14) |
| Mar 23, 2026 | 83.22% (0.83219) | 99.25th | v4 (v2025.03.14) |
| Feb 18, 2026 | 81.96% (0.81961) | 99.17th | v4 (v2025.03.14) |
| Jan 28, 2026 | 83.22% (0.83219) | 99.24th | v4 (v2025.03.14) |
| Dec 28, 2025 | 81.96% (0.81961) | 99.16th | v4 (v2025.03.14) |
| Dec 27, 2025 | 84.08% (0.84076) | 99.27th | v4 (v2025.03.14) |
| Dec 22, 2025 | 81.96% (0.81961) | 99.16th | v4 (v2025.03.14) |
| Nov 21, 2025 | 86.09% (0.86092) | 99.35th | v4 (v2025.03.14) |
| Nov 18, 2025 | 91.27% (0.91271) | 99.73th | v4 (v2025.03.14) |
| Nov 2, 2025 | 86.25% (0.86249) | 99.37th | v4 (v2025.03.14) |
| Nov 1, 2025 | 84.55% (0.84546) | 99.29th | v4 (v2025.03.14) |
| Oct 27, 2025 | 86.94% (0.86936) | 99.39th | v4 (v2025.03.14) |
| Oct 1, 2025 | 85.56% (0.85563) | 99.35th | v4 (v2025.03.14) |
| Aug 28, 2025 | 86.94% (0.86936) | 99.40th | v4 (v2025.03.14) |
| Aug 4, 2025 | 85.70% (0.85704) | 99.33th | v4 (v2025.03.14) |
| Aug 1, 2025 | 83.75% (0.83750) | 99.26th | v4 (v2025.03.14) |
| Jul 17, 2025 | 85.94% (0.85942) | 99.34th | v4 (v2025.03.14) |
| Jul 16, 2025 | 86.97% (0.86973) | 99.39th | v4 (v2025.03.14) |
| Jul 15, 2025 | 84.98% (0.84977) | 99.29th | v4 (v2025.03.14) |
| Jul 14, 2025 | 83.91% (0.83906) | 99.24th | v4 (v2025.03.14) |
| Jul 11, 2025 | 84.98% (0.84977) | 99.29th | v4 (v2025.03.14) |
| Jul 4, 2025 | 83.91% (0.83906) | 99.24th | v4 (v2025.03.14) |
| Jul 1, 2025 | 82.40% (0.82400) | 99.18th | v4 (v2025.03.14) |
| Jun 26, 2025 | 83.91% (0.83906) | 99.23th | v4 (v2025.03.14) |
| Jun 4, 2025 | 85.03% (0.85032) | 99.29th | v4 (v2025.03.14) |
| Jun 1, 2025 | 83.68% (0.83679) | 99.23th | v4 (v2025.03.14) |
| May 23, 2025 | 85.99% (0.85992) | 99.33th | v4 (v2025.03.14) |
| May 21, 2025 | 87.76% (0.87760) | 99.42th | v4 (v2025.03.14) |
| May 6, 2025 | 85.99% (0.85992) | 99.33th | v4 (v2025.03.14) |
| Mar 30, 2025 | 84.62% (0.84618) | 99.28th | v4 (v2025.03.14) |
| Mar 29, 2025 | 87.90% (0.87904) | 99.36th | v4 (v2025.03.14) |
| Mar 28, 2025 | 84.62% (0.84618) | 99.28th | v4 (v2025.03.14) |
| Mar 20, 2025 | 87.00% (0.87005) | 99.42th | v4 (v2025.03.14) |
| Mar 19, 2025 | 89.07% (0.89069) | 99.51th | v4 (v2025.03.14) |
| Mar 17, 2025 | 87.77% (0.87768) | 99.44th | v4 (v2025.03.14) |
| Dec 17, 2024 | 22.53% (0.22531) | 96.51th | v3 (v2023.03.01) |
| Dec 11, 2024 | 9.44% (0.09435) | 94.99th | v3 (v2023.03.01) |
| Oct 16, 2024 | 11.75% (0.11749) | 95.43th | v3 (v2023.03.01) |
| Aug 5, 2024 | 10.16% (0.10159) | 94.96th | v3 (v2023.03.01) |
| Jul 6, 2024 | 11.24% (0.11243) | 95.24th | v3 (v2023.03.01) |
| Jun 22, 2024 | 11.60% (0.11599) | 95.30th | v3 (v2023.03.01) |
| Jun 8, 2024 | 8.67% (0.08668) | 94.52th | v3 (v2023.03.01) |
| May 24, 2024 | 7.70% (0.07700) | 94.16th | v3 (v2023.03.01) |
| May 11, 2024 | 7.66% (0.07664) | 94.14th | v3 (v2023.03.01) |
| Apr 26, 2024 | 6.08% (0.06076) | 93.42th | v3 (v2023.03.01) |
| Apr 13, 2024 | 6.22% (0.06216) | 93.47th | v3 (v2023.03.01) |
| Mar 4, 2024 | 6.11% (0.06114) | 93.34th | v3 (v2023.03.01) |
| Feb 19, 2024 | 7.29% (0.07295) | 93.82th | v3 (v2023.03.01) |
| Feb 7, 2024 | 6.40% (0.06399) | 92.99th | v3 (v2023.03.01) |
| Feb 6, 2024 | 3.39% (0.03394) | 90.51th | v3 (v2023.03.01) |
| Jan 24, 2024 | 2.79% (0.02785) | 89.60th | v3 (v2023.03.01) |
| Dec 4, 2023 | 3.43% (0.03430) | 90.42th | v3 (v2023.03.01) |
| Nov 21, 2023 | 2.44% (0.02436) | 88.81th | v3 (v2023.03.01) |
| Nov 8, 2023 | 2.33% (0.02327) | 88.53th | v3 (v2023.03.01) |
| Oct 2, 2023 | 3.40% (0.03400) | 90.28th | v3 (v2023.03.01) |
| Sep 22, 2023 | 3.38% (0.03381) | 90.27th | v3 (v2023.03.01) |
| Sep 21, 2023 | 7.96% (0.07965) | 93.50th | v3 (v2023.03.01) |
| Aug 28, 2023 | 7.27% (0.07266) | 93.20th | v3 (v2023.03.01) |
| Aug 16, 2023 | 8.29% (0.08286) | 93.53th | v3 (v2023.03.01) |
| Jul 23, 2023 | 7.62% (0.07620) | 93.26th | v3 (v2023.03.01) |
| Jul 14, 2023 | 8.09% (0.08095) | 93.43th | v3 (v2023.03.01) |
| Jul 8, 2023 | 7.65% (0.07651) | 93.25th | v3 (v2023.03.01) |
| May 8, 2023 | 8.84% (0.08838) | 93.57th | v3 (v2023.03.01) |
| Apr 24, 2023 | 8.85% (0.08849) | 93.58th | v3 (v2023.03.01) |
| Apr 14, 2023 | 9.12% (0.09122) | 93.68th | v3 (v2023.03.01) |
| Mar 7, 2023 | 10.38% (0.10378) | 94.02th | v3 (v2023.03.01) |
| Mar 6, 2023 | 53.31% (0.53308) | 98.78th | v2 (v2022.01.01) |
| Nov 5, 2022 | 53.31% (0.53308) | 98.72th | v2 (v2022.01.01) |
| Nov 3, 2022 | 54.84% (0.54841) | 98.74th | v2 (v2022.01.01) |
| Nov 2, 2022 | 5.32% (0.05315) | 89.59th | v2 (v2022.01.01) |
References (55)
- http://packetstormsecurity.com/files/169687/OpenSSL-Security-Advisory-20221101.html Third Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2022/11/01/15 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/01/16 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/01/17 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/01/18 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/01/19 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/01/20 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/01/21 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/01/24 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/02/1 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/02/10 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/02/11 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/02/12 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/02/13 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/02/14 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/02/15 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/02/2 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/02/3 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/02/5 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/02/6 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/02/7 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/02/9 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/03/1 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/03/10 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/03/11 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/03/2 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/03/3 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/03/5 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/03/6 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/03/7 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/11/03/9 mailing-listMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-3602 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2137723 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-408105.html
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=fe3b639dc19b325846f4f6801f2f4604f56e3de3 Broken LinkThird Party Advisory
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fe3b639dc19b325846f4f6801f2f4604f56e3de3
- https://github.com/advisories/GHSA-8rwr-x37p-mx23 Advisory
- https://github.com/alexcrichton/openssl-src-rs/commit/4a31c14f31e1a08c18893a37e304dd1dd4b7daa3
- https://github.com/openssl/openssl/commit/fe3b639dc19b325846f4f6801f2f4604f56e3de3
- https://github.com/rustsec/advisory-db/pull/1452
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/63YRPWPUSX3MBHNPIEJZDKQT6YA7UF6S vendor-advisoryMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DWP23EZYOBDJQP7HP4YU7W2ABU2YDITS vendor-advisoryMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/63YRPWPUSX3MBHNPIEJZDKQT6YA7UF6S
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DWP23EZYOBDJQP7HP4YU7W2ABU2YDITS
- https://nvd.nist.gov/vuln/detail/CVE-2022-3602
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0023 Third Party Advisory
- https://rustsec.org/advisories/RUSTSEC-2022-0064.html
- https://security.gentoo.org/glsa/202211-01 vendor-advisoryIssue TrackingThird Party Advisory
- https://security.netapp.com/advisory/ntap-20221102-0001 Third Party Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-W9sdCc2a vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-3602
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00789.html
- https://www.kb.cert.org/vuls/id/794340 third-party-advisoryThird Party AdvisoryUS Government Resource
- https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/
- https://www.openssl.org/news/secadv/20221101.txt Vendor Advisory
Change history (0)
No recorded changes yet.