Predictable IV in CBC-mode composite cipher suites
LowPublished Oct 12, 2020
s2n uses a predictable IV for CBC-mode cipher suites backed by OpenSSL composite ciphers with TLS versions 1.1 and 1.2. This may allow adaptive chosen-plaintext attacks against s2n servers running on hosts supporting AES-NI. s2n default security policies list CBC-mode ciphers as the last option. Customers of AWS services do not need to take action. s2n users and AWS customers should update client applications to the most recent version. All versions of s2n from commit https://github.com/awslabs/s2n/commit/b3721cbb50f8c3b0bc81594fac1175e1c6d5c849 to https://github.com/awslabs/s2n/commit/0df8de3c5630357ed25b935a5978c63f49bb4108 and built with OpenSSL are affected by this issue. Affected s2n users should fetch s2n commit https://github.com/awslabs/s2n/commit/b74b95563b14d4db50b53c07a779527b729a672e or build s2n with an alternative cryptographic library.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| s2n Product | < v0.10.19 | v0.10.19 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 162022 | Security vulnerability in a third party software, Slurm < 20.11.9 and 21.08.8 | Critical | 20.11.9 |
| May 52022 | Potential denial of service when sending version negotiation or close packets | Medium | v1.1.1 |
| May 192021 | Security vulnerability in a third party software, Slurm < 20.02.07 and 20.11.7 | High | 20.02.07and20.11.7 |
| Dec 142020 | Allocated memory not freed when session ticket is used | Low | v0.10.23 |
| Oct 122020 | Online Certificate Stapling Protocol (OCSP) Revocation check bypass | Low | v0.10.19 |
| Oct 122020 | Server denial-of-service via crafted handshake message | Low | v0.10.19 |