If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup.
Policy processing is enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.
Update (31 March 2023): The description of the policy processing enablement was corrected based on CVE-2023-0466.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-openssl3alpine-linux-upgrade-openssl | Aug 22, 2024 | Dec 13, 2022 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-opensslamazon-linux-2023-upgrade-openssl-debuginfoamazon-linux-2023-upgrade-openssl-debugsourceamazon-linux-2023-upgrade-openssl-develamazon-linux-2023-upgrade-openssl-libsamazon-linux-2023-upgrade-openssl-libs-debuginfoamazon-linux-2023-upgrade-openssl-perl | Feb 17, 2025 | Dec 13, 2022 | |
| Debian | debian-upgrade-openssl | Jul 30, 2024 | Dec 13, 2022 | |
| Http Openssl | openssl-upgrade-latest | Dec 14, 2022 | Dec 13, 2022 | |
| Ibm Aix | ibm-aix-openssl_advisory38 | Jul 27, 2023 | Dec 13, 2022 | |
| Suse | — | suse-upgrade-libopenssl-3-develsuse-upgrade-libopenssl-3-devel-32bitsuse-upgrade-libopenssl3suse-upgrade-libopenssl3-32bitsuse-upgrade-openssl-3suse-upgrade-openssl-3-doc | Dec 21, 2022 | Dec 13, 2022 |
| Ubuntu | ubuntu-upgrade-libssl-docubuntu-upgrade-libssl3ubuntu-upgrade-openssl | May 1, 2023 | Dec 13, 2022 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Dec 13, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub