CVE-2022-3996 — Improper Locking in Openssl
Severity
7.5HIGHNVD
EPSS
0.2%
top 61.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 13
Latest updateApr 25
Description
If an X.509 certificate contains a malformed policy constraint and
policy processing is enabled, then a write lock will be taken twice
recursively. On some operating systems (most widely: Windows) this
results in a denial of service when the affected process hangs. Policy
processing being enabled on a publicly facing server is not considered
to be a common setup.
Policy processing is enabled by passing the `-policy'
argument to the command line utilities or by calling the
`X509_VERIFY_PARAM_set…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages14 packages
Patches
🔴Vulnerability Details
6📋Vendor Advisories
5Debian▶
CVE-2022-3996: openssl - If an X.509 certificate contains a malformed policy constraint and policy proces...↗2022