CVE-2022-3996

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/12/2022
Last modified:
01/08/2024

Description

If an X.509 certificate contains a malformed policy constraint and<br /> policy processing is enabled, then a write lock will be taken twice<br /> recursively. On some operating systems (most widely: Windows) this<br /> results in a denial of service when the affected process hangs. Policy<br /> processing being enabled on a publicly facing server is not considered<br /> to be a common setup.<br /> <br /> Policy processing is enabled by passing the `-policy&amp;#39;<br /> argument to the command line utilities or by calling the<br /> `X509_VERIFY_PARAM_set1_policies()&amp;#39; function.<br /> <br /> Update (31 March 2023): The description of the policy processing enablement<br /> was corrected based on CVE-2023-0466.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.7 (including)