Skip to content
AWSGHSA-7gxc-93xj-596h

Predictable IV in CBC-mode composite cipher suites

LowPublished Oct 12, 2020

s2n uses a predictable IV for CBC-mode cipher suites backed by OpenSSL composite ciphers with TLS versions 1.1 and 1.2. This may allow adaptive chosen-plaintext attacks against s2n servers running on hosts supporting AES-NI. s2n default security policies list CBC-mode ciphers as the last option. Customers of AWS services do not need to take action. s2n users and AWS customers should update client applications to the most recent version. All versions of s2n from commit https://github.com/awslabs/s2n/commit/b3721cbb50f8c3b0bc81594fac1175e1c6d5c849 to https://github.com/awslabs/s2n/commit/0df8de3c5630357ed25b935a5978c63f49bb4108 and built with OpenSSL are affected by this issue. Affected s2n users should fetch s2n commit https://github.com/awslabs/s2n/commit/b74b95563b14d4db50b53c07a779527b729a672e or build s2n with an alternative cryptographic library.

GitHub advisory

Affected versions

PackageAffectedFixed in
s2n
Product
< v0.10.19v0.10.19
Details and references

More AWS advisories

All AWS

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.