There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine in question is not used in operations with the private key itself and an input of the attacker's direct choice. Otherwise the bug can manifest itself as transient authentication and key negotiation failures or reproducible erroneous outcome of public-key operations with specially crafted input. Among EC algorithms only Brainpool P-512 curves are affected and one presumably can attack ECDH key negotiation. Impact was not analyzed in detail, because pre-requisites for attack are considered unlikely. Namely multiple clients have to choose the curve in question and the server has to share the private key among them, neither of which is default behaviour. Even then only clients that chose the curve will be affected.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Aug 30, 2017 | May 4, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 4, 2017 |
| Cisco Apic | — | Upgrade to the latest version of Cisco APIC to resolve this vulnerability. | May 11, 2026 | Nov 14, 2016 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | May 4, 2017 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Feb 3, 2017 |
| Freebsd | — | Upgrade opensslUpgrade openssl-develUpgrade FreeBSDUpgrade linux-c7-openssl-libsUpgrade linux-c6-openssl | Jan 26, 2017 | Nov 10, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | May 4, 2017 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | May 4, 2017 | May 4, 2017 |
| Oracle Solaris | — | Upgrade library/security/openssl/openssl-fips-140 to version 2.0.12-0.175.3.17.0.4.0 on Solaris 11.3Upgrade library/security/openssl to version 1.0.2.11-0.175.3.17.0.4.0 on Solaris 11.3 | May 29, 2017 | May 4, 2017 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Oct 11, 2016 |
| Suse | — | Upgrade npm4Upgrade libopenssl1_0_0-hmacUpgrade libopenssl-1_0_0-develUpgrade libopenssl-1_1-devel-32bitUpgrade libopenssl1_0_0-32bitUpgrade libopenssl1_1Upgrade libopenssl1_0_0Upgrade openssl-docUpgrade openssl-1_0_0Upgrade sles12sp2-docker-imageUpgrade nodejs4-develUpgrade nodejs6Upgrade nodejs6-docsUpgrade libopenssl1_1-hmacUpgrade openssl-1_0_0-docUpgrade openssl-1_1Upgrade libopenssl-develUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_0_0-hmac-32bitUpgrade nodejs6-develUpgrade nodejs4Upgrade libopenssl1_1-32bitUpgrade npm6Upgrade nodejs4-docsUpgrade libopenssl-1_1-develUpgrade opensslUpgrade libopenssl10 | Feb 10, 2017 | Nov 10, 2016 |
| Ubuntu | — | Upgrade libssl1.0.0 | Feb 1, 2017 | Nov 10, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub