Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Amazon Linux 2023: CVE-2023-0216: Important priority package update for openssl

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Feb 7, 2023
Added
Feb 17, 2025
Modified
Jul 9, 2025

Description

An invalid pointer dereference on read can be triggered when an
application tries to load malformed PKCS7 data with the
d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions.
The result of the dereference is an application crash which could
lead to a denial of service attack. The TLS implementation in OpenSSL
does not call this function however third party applications might
call these functions on untrusted data.
A flaw was found in OpenSSL. An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. This may result in an application crash which could lead to a denial of service. The TLS implementation in OpenSSL does not call this function, however, third party applications might call these functions on untrusted data.

Solutions

amazon-linux-2023-upgrade-opensslamazon-linux-2023-upgrade-openssl-debuginfoamazon-linux-2023-upgrade-openssl-debugsourceamazon-linux-2023-upgrade-openssl-develamazon-linux-2023-upgrade-openssl-libsamazon-linux-2023-upgrade-openssl-libs-debuginfoamazon-linux-2023-upgrade-openssl-perl
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.