Severity
9.1CRITICALNVD
EPSS
5.2%
top 10.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27
Latest updateNov 26

Description

Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent to the peer. Impact summary: A buffer overread can have a range of potential consequences such as unexpected application beahviour or a crash. In particular this issue could result in up to 255 bytes of arbitrary private data from memory being sent to the peer leading to a loss of confidentiality. However, only applications that di

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages8 packages

CVEListV5openssl/openssl3.3.03.3.2+5
Alpineopenssl/openssl< 3.0.14-r0+6
Debianopenssl/openssl< 1.1.1w-0+deb11u2+3
CVEListV5python_software_foundation/cpython3.10.0a13.10.0b1+1
Palo Altopaloalto/pan-os

🔴Vulnerability Details

4
CVEList
SSL_select_next_proto buffer overread2024-06-27
GHSA
GHSA-4fc7-mvrr-wv2c: Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory cont2024-06-27
OSV
CVE-2024-5535: Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory cont2024-06-27
OSV
CVE-2024-5535: Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory cont2024-06-27

📋Vendor Advisories

10
Ubuntu
EDK II vulnerabilities2025-11-26
Oracle
Oracle Oracle Communications Risk Matrix: Routing (OpenSSL) — CVE-2024-55352025-04-15
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (OpenSSL) — CVE-2024-55352025-01-15
Microsoft
OpenSSL: CVE-2024-5535 SSL_select_next_proto buffer overread2024-11-12
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Accessibility (OpenSSL) — CVE-2024-55352024-10-15
CVE-2024-5535 — Out-of-bounds Read in Openssl | cvebase