CVE-2022-3996
published 2022-12-13CVE-2022-3996: If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.23%
65.6th percentile
If an X.509 certificate contains a malformed policy constraint and
policy processing is enabled, then a write lock will be taken twice
recursively. On some operating systems (most widely: Windows) this
results in a denial of service when the affected process hangs. Policy
processing being enabled on a publicly facing server is not considered
to be a common setup.
Policy processing is enabled by passing the `-policy'
argument to the command line utilities or by calling the
`X509_VERIFY_PARAM_set1_policies()' function.
Update (31 March 2023): The description of the policy processing enablement
was corrected based on CVE-2023-0466.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 3.0.7-2 (bookworm) | openssl 3.0.7-2 (bookworm) |
| msrc | azl3_edk2_20240223gitedc6681206c1-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_edk2_20240524git3e722403cd16-8_on_azure_linux_3.0 | — | — |
| openssl | openssl | >= 0 < 3.0.7-r2 | 3.0.7-r2 |
| openssl | openssl | >= 0 < 3.0.7-r2 | 3.0.7-r2 |
| openssl | openssl | >= 0 < 3.0.7-r2 | 3.0.7-r2 |
| openssl | openssl | >= 0 < 3.0.7-r2 | 3.0.7-r2 |
| openssl | openssl | >= 0 < 3.0.7-r2 | 3.0.7-r2 |
| openssl | openssl | >= 0 < 3.0.7-r2 | 3.0.7-r2 |
| openssl | openssl | >= 0 < 3.0.7-r2 | 3.0.7-r2 |
| openssl | openssl | >= 0 < 3.0.7-2 | 3.0.7-2 |
| openssl | openssl | >= 0 < 3.0.7-2 | 3.0.7-2 |
| openssl | openssl | >= 0 < 3.0.7-2 | 3.0.7-2 |
| openssl | openssl | >= 0 < 1.1.1-1ubuntu2.1~18.04.22 | 1.1.1-1ubuntu2.1~18.04.22 |
| openssl | openssl | >= 0 < 1.1.1f-1ubuntu2.18 | 1.1.1f-1ubuntu2.18 |
| openssl | openssl | >= 0 < 3.0.2-0ubuntu1.9 | 3.0.2-0ubuntu1.9 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.27+esm7 | 1.0.1f-1ubuntu2.27+esm7 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.20+esm7 | 1.0.2g-1ubuntu4.20+esm7 |
| openssl | openssl | 3.0.0 – 3.0.7 | — |
| paloalto | cortex_data | — | — |
| paloalto | cortex_xdr | — | — |
| paloalto | cortex_xpanse | — | — |
| paloalto | cortex_xsiam | — | — |
| paloalto | cortex_xsoar | — | — |
| paloalto | globalprotect | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
openssl, openssl1.0 vulnerabilities
osv·2023-04-25·CVSS 7.5
CVE-2022-3996 [HIGH] openssl, openssl1.0 vulnerabilities
openssl, openssl1.0 vulnerabilities
It was discovered that OpenSSL was not properly managing file locks when
processing policy constraints. If a user or automated system were tricked
into processing a certificate chain with specially crafted policy
constraints, a remote attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 22.04 LTS and Ubuntu
22.10. (CVE-2022-3996)
David Benjamin discovered that OpenSSL was not properly performing the
verification of X.509 certificate chains that include policy constraints,
which could lead to excessive resource consumption. If a user or automated
system were tricked into processing a specially crafted X.509 certificate
chain that includes policy constraints, a remote attacker could possibly
use this issue
OSV
Denial of service by double-checked locking in openssl-src
osv·2022-12-13
CVE-2022-3996 [HIGH] Denial of service by double-checked locking in openssl-src
Denial of service by double-checked locking in openssl-src
If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the `-policy' argument to the command line utilities or by calling either `X509_VERIFY_PARAM_add0_policy()' or `X509_VERIFY_PARAM_set1_policies()' functions.
OSV
CVE-2022-3996: If an X
osv·2022-12-13·CVSS 7.5
CVE-2022-3996 [HIGH] CVE-2022-3996: If an X
If an X.509 certificate contains a malformed policy constraint and
policy processing is enabled, then a write lock will be taken twice
recursively. On some operating systems (most widely: Windows) this
results in a denial of service when the affected process hangs. Policy
processing being enabled on a publicly facing server is not considered
to be a common setup.
Policy processing is enabled by passing the `-policy'
argument to the command line utilities or by calling the
`X509_VERIFY_PARAM_set1_policies()' function.
Update (31 March 2023): The description of the policy processing enablement
was corrected based on CVE-2023-0466.
OSV
CVE-2022-3996: If an X
osv·2022-12-13·CVSS 7.5
CVE-2022-3996 [HIGH] CVE-2022-3996: If an X
If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function. Update (31 March 2023): The description of the policy processing enablement was corrected based on CVE-2023-0466.
GHSA
Denial of service by double-checked locking in openssl-src
ghsa·2022-12-13
CVE-2022-3996 [HIGH] CWE-667 Denial of service by double-checked locking in openssl-src
Denial of service by double-checked locking in openssl-src
If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the `-policy' argument to the command line utilities or by calling either `X509_VERIFY_PARAM_add0_policy()' or `X509_VERIFY_PARAM_set1_policies()' functions.
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2010-1622 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2023-04-25·CVSS 7.5
CVE-2022-3996 [HIGH] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
It was discovered that OpenSSL was not properly managing file locks when
processing policy constraints. If a user or automated system were tricked
into processing a certificate chain with specially crafted policy
constraints, a remote attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 22.04 LTS and Ubuntu
22.10. (CVE-2022-3996)
David Benjamin discovered that OpenSSL was not properly performing the
verification of X.509 certificate chains that include policy constraints,
which could lead to excessive resource consumption. If a user or automated
system were tricked into processing a specially crafted X.509 certificate
chain that includes policy constrain
Palo Alto
PAN-SA-2022-0007 Impact of OpenSSL 3.0 Vulnerability CVE-2022-3996
vendor_paloalto·2022-12-23·CVSS 7.5
CVE-2022-3996 [HIGH] CWE-667 PAN-SA-2022-0007 Impact of OpenSSL 3.0 Vulnerability CVE-2022-3996
PAN-SA-2022-0007 Impact of OpenSSL 3.0 Vulnerability CVE-2022-3996
The OpenSSL Project has published a vulnerability CVE-2022-3996 that affects OpenSSL versions 3.0.0 through 3.0.7 on December 13, 2022.
CVEs: CVE-2022-3996
Affected products: Cortex Data, Cortex XDR, Cortex XSOAR, Cortex Xpanse, GlobalProtect, PAN-OS, Prisma Access, Prisma Cloud, Prisma SD
Red Hat
openssl: double locking leads to denial of service
vendor_redhat·2022-12-13·CVSS 7.5
CVE-2022-3996 [HIGH] CWE-609 openssl: double locking leads to denial of service
openssl: double locking leads to denial of service
If an X.509 certificate contains a malformed policy constraint and
policy processing is enabled, then a write lock will be taken twice
recursively. On some operating systems (most widely: Windows) this
results in a denial of service when the affected process hangs. Policy
processing being enabled on a publicly facing server is not considered
to be a common setup.
Policy processing is enabled by passing the `-policy'
argument to the command line utilities or by calling the
`X509_VERIFY_PARAM_set1_policies()' function.
Update (31 March 2023): The description of the policy processing enablement
was corrected based on CVE-2023-0466.
A vulnerability was found in OpenSSL. This security flaw occurs if an X.509 certificate contains a malformed p
Microsoft
X.509 Policy Constraints Double Locking
vendor_msrc·2022-12-13·CVSS 7.5
CVE-2022-3996 [HIGH] CWE-667 X.509 Policy Constraints Double Locking
X.509 Policy Constraints Double Locking
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
openssl: openssl
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.c
Debian
CVE-2022-3996: openssl - If an X.509 certificate contains a malformed policy constraint and policy proces...
vendor_debian·2022·CVSS 7.5
CVE-2022-3996 [HIGH] CVE-2022-3996: openssl - If an X.509 certificate contains a malformed policy constraint and policy proces...
If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function. Update (31 March 2023): The description of the policy processing enablement was corrected based on CVE-2023-0466.
Scope: local
bookworm: resolved (fixed in 3.0.7-2)
bullseye: resolved
forky: resolved (fixed in 3.0.7-2)
sid: resolved (fixed in 3.0.7-2)
trixie: resolved (fixed i
Palo Alto
Palo Alto Networks Security Advisories
vendor_paloalto·CVSS 7.5
CVE-2022-3996 [HIGH] Palo Alto Networks Security Advisories
Palo Alto Networks Security Advisories
CVEs: CVE-2022-3996
Affected products: Cortex Data, Cortex XDR, Cortex XSIAM, Cortex XSOAR, Cortex Xpanse, GlobalProtect, PAN-OS, Panorama, Prisma Access, Prisma Browser, Prisma Cloud, Prisma SD
No detection rules found.
No public exploits indexed.
https://github.com/openssl/openssl/commit/7725e7bfe6f2ce8146b6552b44e0d226be7638e7https://www.openssl.org/news/secadv/20221213.txthttps://github.com/openssl/openssl/commit/7725e7bfe6f2ce8146b6552b44e0d226be7638e7https://security.netapp.com/advisory/ntap-20230203-0003/https://www.openssl.org/news/secadv/20221213.txt
2022-12-13
Published