CVE-2024-9143

The OpenSSL low-level curve API flaw: out-of-bounds memory access, in apis almost nothing calls

A genuine memory-safety bug in OpenSSL, in a corner of the library that mainstream protocol use never reaches. A good example of a CVE whose severity on paper does not match its severity on a web server.

OpenSSLNot in CISA’s Known Exploited catalogueEPSS 5.8% chance of an attempt in 30 daysCVSS 4.3CWE-125CWE-787CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

A fixed package version is available on 4 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.

One read-only command. No account, no agent, nothing changed.

What it actually is

Using the low-level GF(2^m) elliptic curve functions with untrusted explicit curve parameters can read or write memory outside the intended buffer.

What an attacker gets: Out-of-bounds read or write in the calling process. OpenSSL itself judged the practical risk low, because of what it takes to reach the code.

When it applies to you, and when it does not

An old package version and a real exposure are different things. These are the conditions this one needs.

  • TLS does not take this path. A normal HTTPS server, mail server or database using OpenSSL for transport does not call these functions.
  • It needs an application deliberately using the low-level curve APIs with curve parameters from an untrusted source, which is rare and usually deliberate cryptographic code.
  • Patch it in the ordinary course of updates. It is on this site as a worked example of reading a CVE in context rather than as an emergency.

Check your own server

Read-only, changes nothing
openssl version -a | head -2

The version and build date. As always, the package version below is the one that decides whether the fix is present.

Fixed package version, per distribution

From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.

ReleaseSource packageStateFixed in
Ubuntu 22.04 LTSopensslFixed3.0.2-0ubuntu1.19
Ubuntu 24.04 LTSopensslFixed3.0.13-0ubuntu3.5
Debian 12 (bookworm)opensslFixed3.0.15-1~deb12u1
Debian 13 (trixie)opensslFixed3.3.2-2
Rocky Linux 9opensslNo advisory names itno advisory for this release names it
AlmaLinux 9opensslNo advisory names itno advisory for this release names it

Install the fix with apt update && apt install --only-upgrade openssl libssl3 on Debian and Ubuntu, or dnf update openssl openssl-libs on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.

What SecAI has recorded about it

Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds memory reads or writes. Impact summary: Out of bound memory writes can lead to an application crash or even a possibility of a remote code execution, however, in all the protocols involving Elliptic Curve Cryptography that we're aware of, either only "named curves" are supported, or, if explicit curve parameters are supported, they specify an X9.62 encoding of binary (GF(2^m)) curves that can't represent problematic input values. Thus the likelihood of existence of a vulnerable application is low. In particular, the X9.62 encoding is used for ECC keys in X.509 certificates, so problematic inputs cannot occur in the context of processing X.509 certificates. Any problematic use-cases would have to be using an "exotic" curve encoding. The affected APIs include: EC_GROUP_new_curve_GF2m(), EC_GROUP_new_from_params(), and various supporting BN_GF2m_*() functions. Applications working with "exotic" explicit binary (GF(2^m)) curve parameters, that make it possible to represent invalid field polynomials with a zero constant term, via the above or similar APIs, may terminate abruptly as a result of reading or writing outside of array bounds. Remote code execution cannot easily be ruled out. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.

Recorded from nvd. Its weakness class is CWE-125 and CWE-787, from NVD.

Read next

Check whether this vulnerability affects your Linux server

One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2024-9143 included. It changes nothing.