Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2023-1255

Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-125 Lectura fuera de límites
Fecha de publicación:
20/04/2023
Última modificación:
04/02/2025

Descripción

*** Pendiente de traducción *** Issue summary: The AES-XTS cipher decryption implementation for 64 bit ARM<br /> platform contains a bug that could cause it to read past the input buffer,<br /> leading to a crash.<br /> <br /> Impact summary: Applications that use the AES-XTS algorithm on the 64 bit ARM<br /> platform can crash in rare circumstances. The AES-XTS algorithm is usually<br /> used for disk encryption.<br /> <br /> The AES-XTS cipher decryption implementation for 64 bit ARM platform will read<br /> past the end of the ciphertext buffer if the ciphertext size is 4 mod 5 in 16<br /> byte blocks, e.g. 144 bytes or 1024 bytes. If the memory after the ciphertext<br /> buffer is unmapped, this will trigger a crash which results in a denial of<br /> service.<br /> <br /> If an attacker can control the size and location of the ciphertext buffer<br /> being decrypted by an application using AES-XTS on 64 bit ARM, the<br /> application is affected. This is fairly unlikely making this issue<br /> a Low severity one.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.0.0 (incluyendo) 3.0.9 (excluyendo)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.1.0 (incluyendo) 3.1.1 (excluyendo)