Allocated memory not freed when session ticket is used
LowPublished Dec 14, 2020
s2n fails to free allocated memory when the session ticket decryption method fails. This could cause the host to run out of memory and force the application to restart. Customers of AWS services do not need to take action. s2n users who are using session resumption in their applications should update to the most recent s2n version. All versions of s2n from commit https://github.com/awslabs/s2n/commit/cc339f5315c04169445cf0d395ab0acc914f9827 to https://github.com/awslabs/s2n/commit/360f62054148ab8fcec78842d2632a9421554def are affected by this issue. s2n users should fetch s2n commit https://github.com/awslabs/s2n/commit/c422355bd15c3cade2a15d1574144b1b6a87cb2c
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| s2n Product | < v0.10.23 | v0.10.23 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 162022 | Security vulnerability in a third party software, Slurm < 20.11.9 and 21.08.8 | Critical | 20.11.9 |
| May 52022 | Potential denial of service when sending version negotiation or close packets | Medium | v1.1.1 |
| May 192021 | Security vulnerability in a third party software, Slurm < 20.02.07 and 20.11.7 | High | 20.02.07and20.11.7 |
| Oct 122020 | Predictable IV in CBC-mode composite cipher suites | Low | v0.10.19 |
| Oct 122020 | Online Certificate Stapling Protocol (OCSP) Revocation check bypass | Low | v0.10.19 |
| Oct 122020 | Server denial-of-service via crafted handshake message | Low | v0.10.19 |