Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations
Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, only applications that directly call the SSL_free_buffers function are affected by this issue. Applications that do not call this function are not vulnerable. Our investigations indicate that this function is rarely used by applications.
The SSL_free_buffers function is used to free the internal OpenSSL buffer used when processing an incoming record from the network. The call is only expected to succeed if the buffer is not currently in use. However, two scenarios have been identified where the buffer is freed even when still in use.
The first scenario occurs where a record header has been received from the network and processed by OpenSSL, but the full record body has not yet arrived. In this case calling SSL_free_buffers will succeed even though a record has only been partially processed and the buffer is still in use.
The second scenario occurs where a full record containing application data has been received and processed by OpenSSL but the application has only read part of this data. Again a call to SSL_free_buffers will succeed even though the buffer is still in use.
While these scenarios could occur accidentally during normal operation a malicious attacker could attempt to engineer a stituation where this occurs. We are not aware of this issue being actively exploited.
The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssl-develUpgrade opensslUpgrade openssl-perlUpgrade openssl-libs | Nov 21, 2024 | Nov 13, 2024 |
| Amazon Linux Ami 2 | — | Upgrade openssl11-debuginfoUpgrade openssl11Upgrade openssl11-develUpgrade openssl11-libsUpgrade openssl11-static | Aug 14, 2024 | Aug 14, 2024 |
| Amazon_linux_2023 | — | Upgrade openssl-libsUpgrade openssl-develUpgrade openssl-snapsafe-libsUpgrade openssl-perlUpgrade openssl-debugsourceUpgrade openssl-snapsafe-libs-debuginfoUpgrade openssl-debuginfoUpgrade opensslUpgrade openssl-libs-debuginfo | Feb 17, 2025 | May 28, 2024 |
| Debian | — | Upgrade openssl | Sep 2, 2024 | Sep 2, 2024 |
| Dell Poweredge Dsa2026316 | — | Upgrade Dell PowerEdge to the latest version | Jul 16, 2026 | Jul 14, 2026 |
| F5 Big Ip | — | — | Jul 31, 2024 | Jul 31, 2024 |
| Freebsd | — | Upgrade openssl31-quictlsUpgrade openssl32Upgrade openssl31Upgrade openssl-quictlsUpgrade openssl33Upgrade openssl | Dec 10, 2025 | May 28, 2024 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Nov 13, 2024 | Nov 13, 2024 |
| Huawei Euleros 2_0_sp10 | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-libs | Oct 8, 2024 | Aug 20, 2024 |
| Huawei Euleros 2_0_sp11 | — | Upgrade openssl-libsUpgrade openssl-perlUpgrade openssl | Oct 8, 2024 | Aug 20, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade openssl-perlUpgrade openssl-libsUpgrade openssl | Oct 8, 2024 | Aug 20, 2024 |
| Huawei Euleros 2_0_sp9 | — | Upgrade opensslUpgrade openssl-perlUpgrade openssl-libs | Oct 8, 2024 | Aug 20, 2024 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory42 | Jul 31, 2024 | Jul 30, 2024 |
| Oracle_linux | — | Upgrade openssl-perlUpgrade openssl-libsUpgrade openssl-fips-provider-soUpgrade opensslUpgrade openssl-fips-providerUpgrade openssl-devel | Nov 21, 2024 | May 28, 2024 |
| Redhat_linux | — | Upgrade openssl-fips-provider-so-debugsourceUpgrade openssl-debuginfoUpgrade openssl-fips-providerUpgrade openssl-fips-provider-soNo solution existsUpgrade openssl-libs-debuginfoUpgrade openssl-debugsourceUpgrade opensslUpgrade openssl-libsUpgrade openssl-perlUpgrade openssl-fips-provider-so-debuginfoUpgrade openssl-devel | Nov 13, 2024 | May 28, 2024 |
| Rocky_linux | — | Upgrade openssl-libs-debuginfoUpgrade opensslUpgrade openssl-debuginfoUpgrade openssl-debugsourceUpgrade openssl-libsUpgrade openssl-perlUpgrade openssl-devel | Mar 18, 2025 | Nov 13, 2024 |
| Suse | — | Upgrade libopenssl-3-fips-provider-x86-64-v3Upgrade openssl-1_1Upgrade openssl-3Upgrade libopenssl3Upgrade libopenssl-3-fips-provider-32bitUpgrade libopenssl-1_1-develUpgrade libopenssl1_1-32bitUpgrade libopenssl-3-develUpgrade libopenssl-3-devel-32bitUpgrade libopenssl1_1-hmac-32bitUpgrade openssl-1_1-docUpgrade libopenssl-3-fips-providerUpgrade openssl-3-docUpgrade libopenssl3-x86-64-v3Upgrade libopenssl1_1Upgrade libopenssl-1_1-devel-32bitUpgrade libopenssl3-32bitUpgrade libopenssl1_1-hmac | Jun 14, 2024 | Jun 13, 2024 |
| Ubuntu | — | Upgrade ovmf-ia32Upgrade qemu-efi-aarch64Upgrade ovmfUpgrade qemu-efiUpgrade qemu-efi-armUpgrade qemu-efi-loongarch64Upgrade libssl1.1Upgrade libssl3t64Upgrade qemu-efi-riscv64Upgrade libssl3 | Aug 1, 2024 | Jul 31, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Nov 13, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub