Skip to content
AWSGHSA-mm47-wjfh-4hf5

Server denial-of-service by using sslv2 message format in a HelloRetryRequest handshake

LowPublished Sep 27, 2022

If a TLS1.3 enabled s2n-tls server receives an sslv2 ClientHello format message in a HelloRetryRequest handshake, the server may restart due to a NULL pointer dereference. Applications using s2n are expected to restart following a NULL pointer dereference, and client applications may also retry requests. No AWS service was impacted by this issue and AWS customers do not need to take any action. s2n-tls users who enabled TLS1.3 in their applications should update to the most recent s2n-tls version. All versions of s2n-tls from commit 397382111523a94f95cc551c4ca4d1eaf884ef35 through commit c947a221e1caadf12a262a6bf548f5f082e096be are affected by this issue. Affected s2n-tls users should fetch s2n-tls commit 8cf81d3976dddb00b0050b0cfafcb41ea2a3bde5.

GitHub advisory

Affected versions

PackageAffectedFixed in
s2n-tls
Product
< <v1.3.23<v1.3.23
Details and references

More AWS advisories

All AWS
Advisory
Issue with parsing Certificate Common Name (CN) in s2n-tls
LowFeb 14, 2023
Privilege Escalation Vector in CloudWatch Agent for Windows
High7.1Dec 10, 2022
Issue with configuring session ticket names in s2n-tls
MediumSep 27, 2022
Partial Path Traversal in aws-cpp-sdk-transfer
MediumAug 9, 2022
Partial Path Traversal in com.amazonaws:aws-java-sdk-s3
High7.9Jul 15, 2022
Security vulnerability in a third party software, Slurm < 20.11.9 and 21.08.8
CriticalMay 16, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.