VDB
Sign up
HIGH7.5

GHSA-vr8j-hgmm-jh9r

Denial of service by double-checked locking in openssl-src

Details

If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the `-policy' argument to the command line utilities or by calling either `X509_VERIFY_PARAM_add0_policy()' or `X509_VERIFY_PARAM_set1_policies()' functions.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/openssl-src
Introduced in: 300.0.0Fixed in: 300.0.12

Upgrade openssl-src to 300.0.12 or newer (ecosystem crates.io).

References