CVE-2022-2097
openssl - security update
7.5
HIGH
CVSS 3.1
EPSS 0.51%
Description
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).
How to fix CVE-2022-2097
To remediate CVE-2022-2097, upgrade the affected package to a fixed version below.
- —upgrade to 1.1.1q-r0 or later
- —upgrade to 3.0.5-r0 or later
- —upgrade to 111.22.0 or later
- —upgrade to 111.22.0 or later
- —upgrade to 1.1.1n-0+deb10u4 or later
- —upgrade to 1.1.1n-0+deb11u4 or later
- —upgrade to 1.1.1n-0+deb11u4 or later
Is CVE-2022-2097 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (7)
- from 0, < 1.1.1q-r0
- from 0, < 3.0.5-r0
- >= 0.0.0-0, < 111.22.0, >= 300.0.0, < 300.0.9
- from 0, < 111.22.0
- from 0, < 1.1.1n-0+deb10u4
- from 0, < 1.1.1n-0+deb11u4
- from 0, < 1.1.1n-0+deb11u4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |