Logo
vulnerabilityCVE-2024-41996
Name
CVE-2024-41996
Source
NVD ( link)Debian ( link)
Description
Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
openssl
Patched

Vulnerability Ratings#


7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.5.7
Not Affected
buildroot
master
3.6.3
Not Affected
openwrt
master
3.5.7-r1
Not Affected
openwrt
openwrt-25.12
3.5.7-r1
Not Affected
yocto
master
3.5.7
Not Affected
yocto
scarthgap
3.5.6
Not Affected

Resolved with patches#


openssl (yocto:kirkstone)

#
Title
Author
Resolve
1
dh_kmgmt.c: Avoid expensive public key validation for known
Tomas Mraz <tomas@openssl.org>
CVE-2024-41996