CVE-2021-23840
published 2021-02-16CVE-2021-23840: Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the…
PriorityP358high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
50.73%
98.8th percentile
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).
Affected
62 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | openssl | < openssl 1.1.1j-1 (bookworm) | openssl 1.1.1j-1 (bookworm) |
| fujitsu | m10-1_firmware | < xcp2410 | xcp2410 |
| fujitsu | m10-1_firmware | < xcp3110 | xcp3110 |
| fujitsu | m10-4_firmware | < xcp2410 | xcp2410 |
| fujitsu | m10-4_firmware | < xcp3110 | xcp3110 |
| fujitsu | m10-4s_firmware | < xcp2410 | xcp2410 |
| fujitsu | m10-4s_firmware | < xcp3110 | xcp3110 |
| fujitsu | m12-1_firmware | < xcp2410 | xcp2410 |
| fujitsu | m12-1_firmware | < xcp3110 | xcp3110 |
| fujitsu | m12-2_firmware | < xcp2410 | xcp2410 |
| fujitsu | m12-2_firmware | < xcp3110 | xcp3110 |
| fujitsu | m12-2s_firmware | < xcp2410 | xcp2410 |
| fujitsu | m12-2s_firmware | < xcp3110 | xcp3110 |
| mcafee | epolicy_orchestrator | < 5.10.0 | 5.10.0 |
| mcafee | epolicy_orchestrator | — | — |
| msrc | azl3_shim-unsigned-aarch64_15.8-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_shim-unsigned-x64_1.1.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_shim-unsigned-x64_15.8-5_on_azure_linux_3.0 | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | 10.0.0 – 10.12.0 | — |
| nodejs | node.js | >= 10.13.0 < 10.24.0 | 10.24.0 |
| nodejs | node.js | 12.0.0 – 12.12.0 | — |
| nodejs | node.js | >= 12.13.0 < 12.21.0 | 12.21.0 |
| nodejs | node.js | 14.0.0 – 14.14.0 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for integer overflow conditions in OpenSSL EVP cipher update functions (EVP_CipherUpdate, EVP_EncryptUpdate, EVP_DecryptUpdate) where the return value is 1 (success) but the output length value is negative — this is the characteristic symptom of exploitation. ↗
- →Alert on abnormal spikes in TLS handshake errors and repeated application crashes during certificate validation, which may indicate active exploitation attempts against vulnerable OpenSSL deployments. ↗
- →Configure SIEM detection rules to flag anomalies in OpenSSL processing functions, particularly around X.509 certificate handling events that precede crashes. ↗
- →Use EDR/host-based tools to identify irregular memory or certificate parsing activity associated with OpenSSL, as the vulnerability can be triggered via malformed X.509 certificates submitted during TLS handshakes. ↗
- →For ICS/OT environments, monitor network traffic to MELSOFT GT OPC UA Client (versions 1.00A–1.02C) and GT SoftGOT2000 (versions 1.215Z–1.270G) for specially crafted messages that could trigger the integer overflow DoS condition. ↗
- ·The vulnerability affects OpenSSL versions 1.1.1i and below (fixed in 1.1.1j) and OpenSSL 1.0.2x and below (fixed in 1.0.2y for premium support customers). Deployments still running these versions are exploitable remotely with low attack complexity over TLS. ↗
- ·The vulnerability is exploitable remotely with no authentication required and low attack complexity (CVSS AV:N/AC:L/PR:N/UI:N), making unpatched internet-facing OpenSSL services high-priority targets. ↗
- ·python-cryptography package before version 3.3.2 is also affected as a downstream consumer of the vulnerable OpenSSL functions; Red Hat notes several product lines will not receive fixes. ↗
- ·No known public exploits specifically targeted the ICS products (MELSOFT GT OPC UA Client / GT SoftGOT2000) at the time of the CISA advisory, but the attack surface is network-accessible. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_redhat9.1CRITICAL
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
vendor_paloalto·2024-11-07·CVSS 6.8
CVE-2014-0195 [MEDIUM] PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Cortex XDR Agent. While Cortex XDR Agent may include the
CVEs: CVE-2014-0195, CVE-2014-0224, CVE-2014-3509, CVE-2014-3512, CVE-2014-3513, CVE-2014-3567, CVE-2015-0209, CVE-2015-0292, CVE-2015-1789, CVE-2015-1791, CVE-2015-1793, CVE-2015-3194, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-2105, CVE-2016-2106, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2177, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2019-1551, CVE-2019-1552, CVE-2019-1559, CVE-2019-1563, CVE-2020-196
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2024-09-18·CVSS 3.7
CVE-2024-0727 [LOW] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Robert Merget, Marcus Brinkmann, Nimrod Aviram, and Juraj Somorovsky
discovered that certain Diffie-Hellman ciphersuites in the TLS
specification and implemented by OpenSSL contained a flaw. A remote
attacker could possibly use this issue to eavesdrop on encrypted
communications. This was fixed in this update by removing the insecure
ciphersuites from OpenSSL. (CVE-2020-1968)
Paul Kehrer discovered that OpenSSL incorrectly handled certain input
lengths in EVP functions. A remote attacker could possibly use this issue
to cause OpenSSL to crash, resulting in a denial of service.
(CVE-2021-23840)
Elison Niven discovered that OpenSSL incorrectly handled the c_rehash
script. A local attacker could possibl
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
CISA ICS
Mitsubishi Electric MELSOFT GT OPC UA
cisa_ics·2022-05-10·CVSS 7.5
[HIGH] Mitsubishi Electric MELSOFT GT OPC UA
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Mitsubishi Electric MELSOFT GT OPC UA
Last RevisedMay 10, 2022
Alert CodeICSA-22-130-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Mitsubishi Electric
- Equipment: MELSOFT GT OPC UA Client
- Vulnerabilities: Out-of-bounds Read, Integer Overflow or Wraparound
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow a remote attacker to send specially crafted messages, resulting in information disclosure or a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
CISA ICS
Hitachi Energy System Data Manager
cisa_ics·2022-04-26·CVSS 7.5
[HIGH] Hitachi Energy System Data Manager
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy System Data Manager
Last RevisedApril 26, 2022
Alert CodeICSA-22-116-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: System Data Manager – SDM600
- Vulnerabilities: Integer Overflow or Wraparound, Reachable Assertion, Type Confusion, Uncontrolled Recursion, Observable Discrepancy
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to eavesdrop on traffic or to cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 A
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Oracle
Oracle Oracle Systems Risk Matrix: XCP Firmware (OpenSSL) — CVE-2021-23840
vendor_oracle·2022-01-15·CVSS 7.5
CVE-2021-23840 [HIGH] Oracle Oracle Systems Risk Matrix: XCP Firmware (OpenSSL) — CVE-2021-23840
Oracle Oracle Systems Risk Matrix: XCP Firmware (OpenSSL) vulnerability
CVE: CVE-2021-23840
CVSS: 7.5
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
CISA ICS
Hitachi Energy APM Edge (Update A)
cisa_ics·2021-12-02·CVSS 9.1
[CRITICAL] Hitachi Energy APM Edge (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy APM Edge (Update A)
Last RevisedOctober 18, 2022
Alert CodeICSA-21-336-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Low attack complexity
- Vendor: Hitachi Energy
- Equipment: Transformer Asset Performance Management (APM) Edge
- Vulnerability: Reliance on Uncontrolled Component
## 2. UPDATE OR REPOSTED INFORMATION
This updated advisory is a follow-up to the original advisory titled “ICSA-21-336-06 Hitachi Energy APM Edge” that was published December 02, 2021, on the ICS webpage on cisa.gov/ics.
## 3. RISK EVALUATION
Successful exploitation of thi
Ubuntu
EDK II vulnerabilities
vendor_ubuntu·2021-09-23·CVSS 6.8
CVE-2019-11098 [MEDIUM] EDK II vulnerabilities
Title: EDK II vulnerabilities
Summary: Several security issues were fixed in EDK II.
It was discovered that EDK II incorrectly handled input validation in
MdeModulePkg. A local user could possibly use this issue to cause EDK II to
crash, resulting in a denial of service, obtain sensitive information or
execute arbitrary code. (CVE-2019-11098)
Paul Kehrer discovered that OpenSSL used in EDK II incorrectly handled
certain input lengths in EVP functions. An attacker could possibly use this
issue to cause EDK II to crash, resulting in a denial of service.
(CVE-2021-23840)
Ingo Schwarze discovered that OpenSSL used in EDK II incorrectly handled
certain ASN.1 strings. An attacker could use this issue to cause EDK II to
crash, resulting in a denial of service, or possibly obtain sensitive
inf
BSD
FreeBSD-SA-21:17.openssl: Multiple vulnerabilities in OpenSSL
bsd_advisories·2021-08-24·CVSS 7.5
CVE-2021-23840 [HIGH] FreeBSD-SA-21:17.openssl: Multiple vulnerabilities in OpenSSL
FreeBSD-SA-21:17.openssl Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in OpenSSL
Category: contrib
Module: openssl
Announced: 2021-08-24
Affects: FreeBSD 12.2 and FreeBSD 11.4
Corrected: 2021-02-18 23:55:09 UTC (stable/12, 12.2-STABLE)
2021-08-24 18:32:22 UTC (releng/12.2, 12.2-RELEASE-p10)
2021-02-19 16:21:03 UTC (stable/11, 11.4-STABLE)
2021-08-24 18:31:34 UTC (releng/11.4, 11.4-RELEASE-p13)
CVE Name: CVE-2021-23840, CVE-2021-23841
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
FreeBSD includes software from the OpenSSL Project. The OpenSSL Project is a
collaborative effort to develop a robust, commercial-grade, full-feature
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2021-02-18·CVSS 7.5
CVE-2021-23841 [HIGH] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Paul Kehrer discovered that OpenSSL incorrectly handled certain input
lengths in EVP functions. A remote attacker could possibly use this issue
to cause OpenSSL to crash, resulting in a denial of service.
(CVE-2021-23840)
Tavis Ormandy discovered that OpenSSL incorrectly handled parsing issuer
fields. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service. (CVE-2021-23841)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
openssl: integer overflow in CipherUpdate
vendor_redhat·2021-02-16·CVSS 7.5
CVE-2021-23840 [HIGH] CWE-190 openssl: integer overflow in CipherUpdate
openssl: integer overflow in CipherUpdate
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users s
Microsoft
Integer overflow in CipherUpdate
vendor_msrc·2021-02-09·CVSS 7.5
CVE-2021-23840 [HIGH] CWE-190 Integer overflow in CipherUpdate
Integer overflow in CipherUpdate
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
openssl: openssl
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-u
Debian
CVE-2021-23840: openssl - Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow ...
vendor_debian·2021·CVSS 7.5
CVE-2021-23840 [HIGH] CVE-2021-23840: openssl - Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow ...
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1
Red Hat
python-cryptography: Large inputs for symmetric encryption can trigger integer overflow leading to buffer overflow
vendor_redhat·2020-12-09·CVSS 9.1
CVE-2020-36242 [CRITICAL] CWE-190 python-cryptography: Large inputs for symmetric encryption can trigger integer overflow leading to buffer overflow
python-cryptography: Large inputs for symmetric encryption can trigger integer overflow leading to buffer overflow
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
A buffer-overflow flaw was found in the python-cryptography package. In certain sequences of ``update()`` calls when symmetrically encrypting very large payloads (>2GB) could result in an integer overflow, leading to buffer overflows. Note: This fix is a workaround for the OpenSSL CVE-2021-23840 flaw. Source: pyca/cryptography project
Statement: Triggering this flaw on in versions of python-cryptography as shipped with Red Hat Enterprise Linux 8 BaseOS, Ap
OSV
openssl vulnerabilities
osv·2024-09-18·CVSS 3.7
CVE-2020-1968 [LOW] openssl vulnerabilities
openssl vulnerabilities
Robert Merget, Marcus Brinkmann, Nimrod Aviram, and Juraj Somorovsky
discovered that certain Diffie-Hellman ciphersuites in the TLS
specification and implemented by OpenSSL contained a flaw. A remote
attacker could possibly use this issue to eavesdrop on encrypted
communications. This was fixed in this update by removing the insecure
ciphersuites from OpenSSL. (CVE-2020-1968)
Paul Kehrer discovered that OpenSSL incorrectly handled certain input
lengths in EVP functions. A remote attacker could possibly use this issue
to cause OpenSSL to crash, resulting in a denial of service.
(CVE-2021-23840)
Elison Niven discovered that OpenSSL incorrectly handled the c_rehash
script. A local attacker could possibly use this issue to execute arbitrary
commands when c_rehash is
OSV
edk2 vulnerabilities
osv·2021-09-23·CVSS 6.8
CVE-2019-11098 [MEDIUM] edk2 vulnerabilities
edk2 vulnerabilities
It was discovered that EDK II incorrectly handled input validation in
MdeModulePkg. A local user could possibly use this issue to cause EDK II to
crash, resulting in a denial of service, obtain sensitive information or
execute arbitrary code. (CVE-2019-11098)
Paul Kehrer discovered that OpenSSL used in EDK II incorrectly handled
certain input lengths in EVP functions. An attacker could possibly use this
issue to cause EDK II to crash, resulting in a denial of service.
(CVE-2021-23840)
Ingo Schwarze discovered that OpenSSL used in EDK II incorrectly handled
certain ASN.1 strings. An attacker could use this issue to cause EDK II to
crash, resulting in a denial of service, or possibly obtain sensitive
information. (CVE-2021-3712)
It was discovered that EDK II incorrec
GHSA
Integer Overflow in openssl-src
ghsa·2021-08-25
CVE-2021-23840 [HIGH] CWE-190 Integer Overflow in openssl-src
Integer Overflow in openssl-src
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgr
OSV
Integer Overflow in openssl-src
osv·2021-08-25
CVE-2021-23840 [HIGH] Integer Overflow in openssl-src
Integer Overflow in openssl-src
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgr
OSV
Integer overflow in CipherUpdate
osv·2021-05-01
CVE-2021-23840 Integer overflow in CipherUpdate
Integer overflow in CipherUpdate
Calls to `EVP_CipherUpdate`, `EVP_EncryptUpdate` and `EVP_DecryptUpdate` may overflow
the output length argument in some cases where the input length is close to the
maximum permissable length for an integer on the platform. In such cases the
return value from the function call will be 1 (indicating success), but the
output length value will be negative. This could cause applications to behave
incorrectly or crash.
OSV
openssl, openssl1.0 vulnerabilities
osv·2021-02-18·CVSS 7.5
CVE-2021-23840 [HIGH] openssl, openssl1.0 vulnerabilities
openssl, openssl1.0 vulnerabilities
Paul Kehrer discovered that OpenSSL incorrectly handled certain input
lengths in EVP functions. A remote attacker could possibly use this issue
to cause OpenSSL to crash, resulting in a denial of service.
(CVE-2021-23840)
Tavis Ormandy discovered that OpenSSL incorrectly handled parsing issuer
fields. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service. (CVE-2021-23841)
OSV
CVE-2021-23840: Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is clo
osv·2021-02-16·CVSS 7.5
CVE-2021-23840 [HIGH] CVE-2021-23840: Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is clo
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1
No detection rules found.
No public exploits indexed.
HackerOne
Integer overflow in CipherUpdate
hackerone·2021-04-08·CVSS 9.1
CVE-2021-23840 [CRITICAL] Integer overflow in CipherUpdate
Integer overflow in CipherUpdate
## Summary:
I reported an integer overflow to the OpenSSL security list on Dec 13, 2020 and it was fixed in OpenSSL 1.1.1j. Reporting it here for the bounty. It was assigned CVE-2021-23840 (https://nvd.nist.gov/vuln/detail/CVE-2021-23840) which NVD rated CVSS 7.5. Amusingly, the same bug (worked around by my library pyca/cryptography before 1.1.1j was released) was assigned CVE-2020-36242 (https://nvd.nist.gov/vuln/detail/CVE-2020-36242), which received a 9.1 CVSS from NVD.
## Steps To Reproduce:
The below is a reproducer for prior to 1.1.1j.
```
#include
#include
#include
#include
int main() {
int res;
EVP_CIPHER_CTX *ctx = EVP_CIPHER_CTX_new();
assert(ctx != NULL);
unsigned char key[] = "0000000000000000";
unsigned char iv[] = "0000000000000000";
res =
Bugzilla
CVE-2021-23841 openssl: NULL pointer dereference in X509_issuer_and_serial_hash()
bugzilla·2021-02-18·CVSS 5.9
CVE-2021-23841 [MEDIUM] CVE-2021-23841 openssl: NULL pointer dereference in X509_issuer_and_serial_hash()
CVE-2021-23841 openssl: NULL pointer dereference in X509_issuer_and_serial_hash()
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1
Bugzilla
CVE-2021-23840 openssl: integer overflow in CipherUpdate
bugzilla·2021-02-18·CVSS 7.5
CVE-2021-23840 [HIGH] CVE-2021-23840 openssl: integer overflow in CipherUpdate
CVE-2021-23840 openssl: integer overflow in CipherUpdate
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y
Huntress
CVE-2021-23840 Vulnerability: Analysis, Detection, Removal | Huntress
blogs_huntress·CVSS 7.5
CVE-2021-23840 [HIGH] CVE-2021-23840 Vulnerability: Analysis, Detection, Removal | Huntress
## CVE-2021-23840 Vulnerability
Published: 12/05/2025
Written by: Lizzie Danielson
## What is CVE-2021-23840 Vulnerability?
CVE-2021-23840 is a buffer overflow vulnerability affecting OpenSSL , categorized as a memory handling issue. Specifically, it impacts the X509_aux_print() function within OpenSSL 1.1.1i and earlier versions, potentially allowing an attacker to exploit the flaw for denial-of-service (DoS) attacks. The vulnerability arises when malformed data is passed to processes handling certain certificate parsing functions. Due to its association with widely used cryptographic libraries, it poses serious risks to data security and system availability.
## When was it discovered?
CVE-2021-23840 was publicly disclosed on February 16, 2021, by the OpenSSL team. The vulnerability
arXiv
VERCATION: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
arxiv_fulltext·2025-08-14
VERCATION: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
Vercation: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
Yiran Cheng12,
Ting Zhang35,
Lwin Khin Shar3,
Shouguo Yang4,
Chaopeng Dong12,
David Lo3,
Shichao Lv125,
Zhiqiang Shi12,
Limin Sun12
1 Beijing Key Laboratory of IOT Information Security Technology,
Institute of Information Engineering, Beijing, China
2 School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China
3 Singapore Management University, Singapore
4 Zhongguancun Laboratory, Beijing, China
[email protected], [email protected], [email protected], \yangshouguo, dongchaopeng\@iie.ac.cn, [email protected], \lvshichao, shizhiqiang, sunlimin\@iie.ac.cn
Journal of \ Class Files, Vol. 14, No. 8, August 2025
Shell et al.: A Sample Article
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=6a51b9e1d0cf0bf8515f7201b68fb0a3482b3dc1https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9b1129239f3ebb1d1c98ce9ed41d5c9476c47cb2https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44846https://kc.mcafee.com/corporate/index?page=content&id=SB10366https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://security.gentoo.org/glsa/202103-03https://security.netapp.com/advisory/ntap-20210219-0009/https://security.netapp.com/advisory/ntap-20240621-0006/https://www.debian.org/security/2021/dsa-4855https://www.openssl.org/news/secadv/20210216.txthttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.tenable.com/security/tns-2021-03https://www.tenable.com/security/tns-2021-09https://www.tenable.com/security/tns-2021-10https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=6a51b9e1d0cf0bf8515f7201b68fb0a3482b3dc1https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9b1129239f3ebb1d1c98ce9ed41d5c9476c47cb2https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44846https://kc.mcafee.com/corporate/index?page=content&id=SB10366https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://security.gentoo.org/glsa/202103-03https://security.netapp.com/advisory/ntap-20210219-0009/https://security.netapp.com/advisory/ntap-20240621-0006/https://www.debian.org/security/2021/dsa-4855https://www.openssl.org/news/secadv/20210216.txthttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.tenable.com/security/tns-2021-03https://www.tenable.com/security/tns-2021-09https://www.tenable.com/security/tns-2021-10
2021-02-16
Published