CVE-2024-9143Out-of-bounds Read in Openssl

Severity
4.3MEDIUMNVD
OSV7.4OSV6.3OSV4.1
EPSS
0.6%
top 29.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateNov 28

Description

Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds memory reads or writes. Impact summary: Out of bound memory writes can lead to an application crash or even a possibility of a remote code execution, however, in all the protocols involving Elliptic Curve Cryptography that we're aware of, either only "named curves" are supported, or, if explicit curve parameters are supported, they specify an X9.62 en

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages21 packages

debiandebian/openssl< openssl 3.0.15-1~deb12u1 (bookworm)
CVEListV5openssl/openssl3.3.03.3.3+5
Ubuntutianocore/edk2< 2022.02-3ubuntu0.22.04.5+3
Alpineopenssl/openssl< 3.0.15-r1+6
Debianopenssl/openssl< 1.1.1w-0+deb11u2+3

🔴Vulnerability Details

7
OSV
edk2 regression2025-11-28
OSV
edk2 vulnerabilities2025-11-26
OSV
openssl vulnerabilities2025-02-20
OSV
openssl vulnerabilities2025-02-11
OSV
CVE-2024-9143: Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds memo2024-10-16

📋Vendor Advisories

14
Ubuntu
EDK II regression2025-11-28
Ubuntu
EDK II vulnerabilities2025-11-26
Oracle
Oracle Oracle JD Edwards Risk Matrix: Enterprise Infrastructure SEC (OpenSSL) — CVE-2024-91432025-10-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (OpenSSL) — CVE-2024-91432025-07-15
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Mod_Security (OpenSSL) — CVE-2024-91432025-04-15

📄Research Papers

1
arXiv
Explainer-guided Targeted Adversarial Attacks against Binary Code Similarity Detection Models2025-06-05
CVE-2024-9143 — Out-of-bounds Read in Openssl | cvebase