Server denial-of-service via crafted handshake message
LowPublished Oct 12, 2020
NULL pointer dereference in s2n_handshake_read_io() Server or client applications that receive an application data message in the final handshake record before the TLS handshake is complete will crash due to a NULL pointer dereference. To exploit this issue, an adversary must go through a full handshake sequence and send a handcrafted TLS record to trigger a remote crash of the application. Applications using s2n are expected to restart following a NULL pointer dereference, and client applications may also retry requests. No AWS service was impacted by this issue and AWS customers do not need to take any action. All versions of s2n through commit [https://github.com/awslabs/s2n/commit/0df8de3c5630357ed25b935a5978c63f49bb4108](https://github.com/awslabs/s2n/commit/0df8de3c5630357ed25b935a5978c63f49bb4108) are affected by this issue. Affected s2n users should fetch s2n commit [https://github.com/awslabs/s2n/commit/b74b95563b14d4db50b53c07a779527b729a672e](https://github.com/awslabs/s2n/commit/b74b95563b14d4db50b53c07a779527b729a672e).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| s2n Product | < v0.10.19 | v0.10.19 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 162022 | Security vulnerability in a third party software, Slurm < 20.11.9 and 21.08.8 | Critical | 20.11.9 |
| May 52022 | Potential denial of service when sending version negotiation or close packets | Medium | v1.1.1 |
| May 192021 | Security vulnerability in a third party software, Slurm < 20.02.07 and 20.11.7 | High | 20.02.07and20.11.7 |
| Dec 142020 | Allocated memory not freed when session ticket is used | Low | v0.10.23 |
| Oct 122020 | Predictable IV in CBC-mode composite cipher suites | Low | v0.10.19 |
| Oct 122020 | Online Certificate Stapling Protocol (OCSP) Revocation check bypass | Low | v0.10.19 |