If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup.
Policy processing is enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.
Update (31 March 2023): The description of the policy processing enablement was corrected based on CVE-2023-0466.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl3Upgrade openssl | Aug 22, 2024 | Dec 13, 2022 |
| Amazon_linux_2023 | — | Upgrade openssl-libs-debuginfoUpgrade openssl-perlUpgrade opensslUpgrade openssl-debuginfoUpgrade openssl-debugsourceUpgrade openssl-libsUpgrade openssl-devel | Feb 17, 2025 | Dec 13, 2022 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Dec 13, 2022 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Dec 14, 2022 | Dec 13, 2022 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory38 | Jul 27, 2023 | Dec 13, 2022 |
| Suse | — | Upgrade libopenssl3-32bitUpgrade libopenssl-3-devel-32bitUpgrade openssl-3-docUpgrade openssl-3Upgrade libopenssl-3-develUpgrade libopenssl3 | Dec 21, 2022 | Dec 13, 2022 |
| Ubuntu | — | Upgrade libssl3Upgrade libssl-docUpgrade openssl | May 1, 2023 | Dec 13, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 13, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub