Severity
7.8HIGHNVD
EPSS
0.7%
top 28.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8
Latest updateApr 7

Description

Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications on the Windows 64 platform when running on newer X86_64 processors supporting the AVX512-IFMA instructions. Impact summary: If in an application that uses the OpenSSL library an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various application dependent consequences. The POLY1305 MAC

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages17 packages

NVDopenssl/openssl1.1.11.1.1w+2
Alpineopenssl/openssl< 0+8
Linuxlinux/linux_kernel5.12.05.15.127+2

Patches

🔴Vulnerability Details

3
OSV
net: core: remove unnecessary frame_sz check in bpf_xdp_adjust_tail()2025-12-24
GHSA
GHSA-53wr-cx66-4578: Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications on t2023-09-08
OSV
CVE-2023-4807: Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications on t2023-09-08

📋Vendor Advisories

11
CISA ICS
Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products (Update D)2026-04-07
CISA ICS
Mitsubishi Electric MELSOFT MaiLab and MELSOFT VIXIO (Update A)2025-05-15
CISA ICS
Siemens SIDIS Prime2025-04-10
CISA ICS
Siemens SINEC NMS2024-11-14
CISA ICS
Siemens SINEC INS2024-11-14
CVE-2023-4807 — Expected Behavior Violation in Openssl | cvebase