All vulnerabilities

CVE-2022-2097

AES OCB fails to encrypt some bytes

Description

AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimisedimplementation will not encrypt the entirety of the data under somecircumstances. This could reveal sixteen bytes of data that waspreexisting in the memory that wasn't written. In the special case of"in place" encryption, sixteen bytes of the plaintext would be revealed.

Since OpenSSL does not support OCB based cipher suites for TLS and DTLS,they are both unaffected.

Patch Available

Fix available through Seal Security. 

No upgrade required, protect your application instantly.

Fix without upgrading
Score
Severity
Ecosystem
RPM
Publish Date
July 5, 2022
Modified Date
November 7, 2023
Score Vector
Affected Versions