cbcvebase.
CVE-2022-3996
published 2022-12-13

CVE-2022-3996: If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some…

PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.23%
65.6th percentile
If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function. Update (31 March 2023): The description of the policy processing enablement was corrected based on CVE-2023-0466.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianopenssl< openssl 3.0.7-2 (bookworm)openssl 3.0.7-2 (bookworm)
msrcazl3_edk2_20240223gitedc6681206c1-2_on_azure_linux_3.0
msrcazl3_edk2_20240524git3e722403cd16-8_on_azure_linux_3.0
opensslopenssl>= 0 < 3.0.7-r23.0.7-r2
opensslopenssl>= 0 < 3.0.7-r23.0.7-r2
opensslopenssl>= 0 < 3.0.7-r23.0.7-r2
opensslopenssl>= 0 < 3.0.7-r23.0.7-r2
opensslopenssl>= 0 < 3.0.7-r23.0.7-r2
opensslopenssl>= 0 < 3.0.7-r23.0.7-r2
opensslopenssl>= 0 < 3.0.7-r23.0.7-r2
opensslopenssl>= 0 < 3.0.7-23.0.7-2
opensslopenssl>= 0 < 3.0.7-23.0.7-2
opensslopenssl>= 0 < 3.0.7-23.0.7-2
opensslopenssl>= 0 < 1.1.1-1ubuntu2.1~18.04.221.1.1-1ubuntu2.1~18.04.22
opensslopenssl>= 0 < 1.1.1f-1ubuntu2.181.1.1f-1ubuntu2.18
opensslopenssl>= 0 < 3.0.2-0ubuntu1.93.0.2-0ubuntu1.9
opensslopenssl>= 0 < 1.0.1f-1ubuntu2.27+esm71.0.1f-1ubuntu2.27+esm7
opensslopenssl>= 0 < 1.0.2g-1ubuntu4.20+esm71.0.2g-1ubuntu4.20+esm7
opensslopenssl3.0.0 – 3.0.7
paloaltocortex_data
paloaltocortex_xdr
paloaltocortex_xpanse
paloaltocortex_xsiam
paloaltocortex_xsoar
paloaltoglobalprotect

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.