Am I affected?

This record states its affected versions in a form that can't be compared automatically.

10.2 and up affected
11.7.4 not affected
11.6.0.4 not affected
11.2.12.11 not affected
every other version: unaffected

Description

The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. In ssl_certificate:handle_incomplete_chain/5, the received chain is passed to ssl_certificate:build_certificate_chain/5, which walks issuer relationships via ssl_certificate:do_certificate_chain/7 with no cycle detection and no depth limit. When the peer supplies two mutually cross-signed certificates in unordered form (A issues B, B issues A), the issuer lookup alternates between the two certificates and the pair of functions recurses indefinitely, growing the call stack and chain accumulator without bound.

An unauthenticated remote attacker can send a crafted certificate chain in a TLS or DTLS Certificate handshake message to exhaust available memory and crash the BEAM node. Only a TCP connection and a partial handshake are required; no authentication or completed handshake is needed, and both TLS/DTLS servers and clients are affected when processing peer certificate messages.

This issue affects OTP from OTP 23.2 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to ssl from 10.2 before 11.7.4, 11.6.0.4 and 11.2.12.11.

Weaknesses & attack patterns

Weakness

CWE-674 · Uncontrolled Recursion in catalog → MITRE ↗

Attack patterns

CAPEC-130 · Excessive Allocation MITRE ↗

Affected — Erlang / ssl Repository ↗

10.2 and up affected
11.7.4 not affected
11.6.0.4 not affected
11.2.12.11 not affected
every other version: unaffected
default status unaffected
cpe cpe:2.3:a:erlang:erlang/otp:*:*:*:*:*:*:*:*
modules · source files · routines
modules ssl_certificate
source files src/ssl_certificate.erl
routines ssl_certificate:handle_incomplete_chain/5 · ssl_certificate:build_certificate_chain/5 · ssl_certificate:do_certificate_chain/7

Affected — GitHub / erlang/otp Repository ↗

23.2 and up affected
29.0.4 not affected
28.5.0.4 not affected
27.3.4.15 not affected
addc42d and up affected
7db6472 not affected
241d437 not affected
0307bff not affected
every other version: unaffected
default status unaffected
cpe cpe:2.3:a:erlang:erlang/otp:*:*:*:*:*:*:*:*
modules · source files · routines
modules ssl_certificate
source files lib/ssl/src/ssl_certificate.erl
routines ssl_certificate:handle_incomplete_chain/5 · ssl_certificate:build_certificate_chain/5 · ssl_certificate:do_certificate_chain/7

References

Credits

Lukas Backström Finder
Ingela Anderton Andin Remediation developer
Dan Gudmundsson Remediation reviewer
Jakub Witczak Remediation reviewer
John Högberg Remediation reviewer

CVSS breakdown

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
« All CVEs