In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the "out" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data to overflow the buffer by up to a maximum of 62 bytes altering the contents of other data held after the buffer, possibly changing application behaviour or causing the application to crash. The location of the buffer is application dependent but is typically heap allocated. Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k).
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl3Upgrade openssl1.1-compatUpgrade openssl | Mar 26, 2024 | Aug 24, 2021 |
| Debian | — | Upgrade openssl | Aug 26, 2021 | Aug 24, 2021 |
| Freebsd | — | Upgrade mysql80-clientUpgrade FreeBSDUpgrade mysql80-serverUpgrade mysql-connector-javaUpgrade mariadb104-serverUpgrade openssl-develUpgrade mysql57-serverUpgrade opensslUpgrade mariadb103-serverUpgrade mariadb105-server | Nov 4, 2022 | Oct 17, 2021 |
| Gentoo Linux | — | Upgrade dev-libs/openssl.Upgrade app-backup/tsm. | Sep 8, 2022 | Aug 24, 2021 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Aug 25, 2021 | Aug 24, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssl111d-develUpgrade openssl111d-staticUpgrade openssl111d-libsUpgrade openssl111d | Nov 12, 2021 | Aug 24, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssl-develUpgrade openssl-perlUpgrade openssl-libsUpgrade openssl | Nov 2, 2021 | Aug 24, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade openssl-libsUpgrade openssl-perlUpgrade openssl | Nov 12, 2021 | Aug 24, 2021 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2022 to the latest version in the current channel channel.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.9 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2022 to the latest version in the LTSC 17.0 version stream, or upgrade to a newer supported version of Visual Studio 2022.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.7 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.11 version stream, or upgrade to a newer supported version of Visual Studio 2019. | Jun 25, 2025 | Nov 9, 2021 |
| Oracle Mysql | — | Upgrade to MySQL version 5.7.36Upgrade to MySQL version 8.0.27 | Jun 15, 2026 | Aug 24, 2021 |
| Oracle Solaris | — | Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-0.175.3.36.0.27.0 on Solaris 11.3Upgrade library/security/openssl to version 1.0.2.26-0.175.3.36.0.27.0 on Solaris 11.3Upgrade database/mysql-57 to version 5.7.36-11.4.42.0.1.113.0 on Solaris 11.4Upgrade library/security/openssl-11 to version 1.1.1.12-11.4.38.0.1.101.4 on Solaris 11.4Upgrade database/mysql-57/embedded to version 5.7.36-11.4.42.0.1.113.0 on Solaris 11.4Upgrade database/mysql-57/client to version 5.7.36-11.4.42.0.1.113.0 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.26-11.4.38.0.1.101.4 on Solaris 11.4Upgrade database/mysql-57/library to version 5.7.36-11.4.42.0.1.113.0 on Solaris 11.4Upgrade database/mysql-57/tests to version 5.7.36-11.4.42.0.1.113.0 on Solaris 11.4 | Nov 17, 2021 | Aug 24, 2021 |
| Suse | — | Upgrade libopenssl-1_1-devel-32bitUpgrade libopenssl1_1-32bitUpgrade libopenssl-1_1-develUpgrade prometheus-postgres_exporterUpgrade golang-github-prometheus-promuUpgrade openssl-1_1-docUpgrade dracut-saltbootUpgrade openssl-1_1Upgrade libopenssl1_1Upgrade python3-rhnlibUpgrade libopenssl1_1-hmac-32bitUpgrade grafanaUpgrade golang-github-prometheus-node_exporterUpgrade spacecmdUpgrade golang-github-boynux-squid_exporterUpgrade libopenssl1_1-hmacUpgrade wireUpgrade prometheus-blackbox_exporter | Aug 25, 2021 | Aug 24, 2021 |
| Ubuntu | — | Upgrade libssl1.1 | Aug 25, 2021 | Aug 24, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 24, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub