CVE-2023-2650Allocation of Resources Without Limits or Throttling in Openssl

Severity
6.5MEDIUMNVD
OSV7.5OSV7.4OSV5.9
EPSS
92.0%
top 0.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 30
Latest updateApr 7

Description

Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service. An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages28 packages

debiandebian/openssl< openssl 3.0.9-1 (bookworm)
CVEListV5openssl/openssl3.1.13.1.1
NVDopenssl/openssl1.0.21.0.2zh+3
Alpineopenssl/openssl< 1.1.1u-r0+8
Debianopenssl/openssl< 1.1.1n-0+deb11u5+3

Also affects: Debian Linux 10.0, 11.0

Patches

🔴Vulnerability Details

7
OSV
edk2 regression2025-11-28
OSV
edk2 vulnerabilities2025-11-26
OSV
nodejs vulnerabilities2024-03-04
OSV
CVE-2023-2650: Issue summary: Processing some specially crafted ASN2023-05-30
GHSA
GHSA-gqxg-9vfr-p9cg: Issue summary: Processing some specially crafted ASN2023-05-30

📋Vendor Advisories

17
CISA ICS
Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products (Update D)2026-04-07
Ubuntu
EDK II regression2025-11-28
Ubuntu
EDK II vulnerabilities2025-11-26
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent2024-11-07
CISA ICS
Mitsubishi Electric CC-Link IE TSN Industrial Managed Switch2024-06-06
CVE-2023-2650 — Openssl vulnerability | cvebase