Bug 2283757 (CVE-2024-4741)
Summary: | CVE-2024-4741 openssl: Use After Free with SSL_free_buffers | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | ybuenos |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | NEW --- | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | ahrabovs, akostadi, amasferr, aucunnin, bdettelb, caswilli, cbartlet, chazlett, crizzo, csutherl, dfreiber, dkuc, dmayorov, doconnor, drow, fjansen, hkataria, jburrell, jcantril, jclere, jdobes, jlledo, jmitchel, jsamir, jsherril, jtanner, jvasik, kaycoth, kholdawa, kshier, kyoshida, lcouzens, mkudlej, mmakovy, mskarbek, mstoklus, orabin, pjindal, plodge, psegedy, rblanco, rojacob, sidakwo, sthirugn, szappis, teagle, tjochec, vkrizan, vkumar, vmugicag |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | openssl 3.3.1, openssl 3.2.2, openssl 3.1.6, openssl 3.0.14, openssl 1.1.1y | Doc Type: | If docs needed, set a value |
Doc Text: |
A use-after-free vulnerability was found in OpenSSL. Calling the OpenSSL API SSL_free_buffers function may cause memory to be accessed that was previously freed in some situations.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2283762, 2283763, 2283764, 2283765, 2283766, 2283767, 2283768, 2283769, 2283770, 2283771, 2283772, 2283773, 2283774, 2283775, 2283776, 2283777, 2283778, 2283779 | ||
Bug Blocks: | 2283780 |
Description
ybuenos
2024-05-29 09:07:59 UTC
Created edk2 tracking bugs for this issue: Affects: fedora-39 [bug 2283764] Affects: fedora-40 [bug 2283768] Created mingw-openssl tracking bugs for this issue: Affects: fedora-39 [bug 2283765] Affects: fedora-40 [bug 2283769] Created openssl tracking bugs for this issue: Affects: fedora-39 [bug 2283766] Affects: fedora-40 [bug 2283770] Created openssl1.1 tracking bugs for this issue: Affects: fedora-39 [bug 2283767] Created openssl11 tracking bugs for this issue: Affects: epel-7 [bug 2283762] Created openssl3 tracking bugs for this issue: Affects: epel-8 [bug 2283763] Created edk2 tracking bugs for this issue: Affects: fedora-39 [bug 2283773] Affects: fedora-40 [bug 2283777] Created mingw-openssl tracking bugs for this issue: Affects: fedora-39 [bug 2283774] Affects: fedora-40 [bug 2283778] Created openssl tracking bugs for this issue: Affects: fedora-39 [bug 2283775] Affects: fedora-40 [bug 2283779] Created openssl1.1 tracking bugs for this issue: Affects: fedora-39 [bug 2283776] Created openssl11 tracking bugs for this issue: Affects: epel-7 [bug 2283771] Created openssl3 tracking bugs for this issue: Affects: epel-8 [bug 2283772] This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:9333 https://access.redhat.com/errata/RHSA-2024:9333 |