{"id":"CVE-2023-0286","title":"openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)","summary":"A type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability ma…","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","cvssSource":"vendor","cwe":"CWE-704","vendor":"Red Hat","product":"Red Hat Enterprise Linux AppStream (v. 9)","affected":["enterprise_linux 7","jboss_web_server 3","enterprise_linux_server_v_6_els","enterprise_linux_server_optional_v_6_els","enterprise_linux_client_v_7","enterprise_linux_client_optional_v_7","enterprise_linux_computenode_optional_v_7","enterprise_linux_server_aus_v_7_7","enterprise_linux_server_v_7","jboss_core_services_on_rhel_7_server","jboss_web_server_5_7_for_rhel_7_server","enterprise_linux_server_optional_aus_v_7_7","enterprise_linux_server_optional_v_7","enterprise_linux_workstation_v_7","enterprise_linux_workstation_optional_v_7","jboss_core_services_on_rhel 8","jboss_web_server_5_7_for_rhel 8","virtualization_4_hypervisor_for_rhel 8","jboss_web_server_5_7_for_rhel 9","rhol_5_9_for_rhel 9","enterprise_linux_appstream_v_8","enterprise_linux_appstream_aus_v_8_2","enterprise_linux_appstream_e4s_v_8_2","enterprise_linux_appstream_tus_v_8_2","enterprise_linux_appstream_aus_v_8_4","enterprise_linux_appstream_e4s_v_8_4","enterprise_linux_appstream_tus_v_8_4","enterprise_linux_appstream_eus_v_8_6","enterprise_linux_appstream_eus_v_9_0","enterprise_linux_appstream_v_9","enterprise_linux_appstream_eus_v_9_4","enterprise_linux_baseos_e4s_v_8_1","enterprise_linux_baseos_aus_v_8_2","enterprise_linux_baseos_e4s_v_8_2","enterprise_linux_baseos_tus_v_8_2","enterprise_linux_baseos_eus_v_8_4","enterprise_linux_baseos_eus_v_8_6","enterprise_linux_baseos_v_8","enterprise_linux_baseos_eus_v_9_0","enterprise_linux_baseos_v_9"],"patched":["enterprise_linux_server_v_6_els","enterprise_linux_server_optional_v_6_els","enterprise_linux_client_v_7","enterprise_linux_client_optional_v_7","enterprise_linux_computenode_optional_v_7","enterprise_linux_server_aus_v_7_7","enterprise_linux_server_v_7","jboss_core_services_on_rhel_7_server","jboss_web_server_5_7_for_rhel_7_server","enterprise_linux_server_optional_aus_v_7_7","enterprise_linux_server_optional_v_7","enterprise_linux_workstation_v_7","enterprise_linux_workstation_optional_v_7","jboss_core_services_on_rhel 8","jboss_web_server_5_7_for_rhel 8","virtualization_4_hypervisor_for_rhel 8","jboss_web_server_5_7_for_rhel 9","rhol_5_9_for_rhel 9","enterprise_linux_appstream_v_8","enterprise_linux_appstream_aus_v_8_2","enterprise_linux_appstream_e4s_v_8_2","enterprise_linux_appstream_tus_v_8_2","enterprise_linux_appstream_aus_v_8_4","enterprise_linux_appstream_e4s_v_8_4","enterprise_linux_appstream_tus_v_8_4","enterprise_linux_appstream_eus_v_8_6","enterprise_linux_appstream_eus_v_9_0","enterprise_linux_appstream_v_9","enterprise_linux_appstream_eus_v_9_4","enterprise_linux_baseos_e4s_v_8_1","enterprise_linux_baseos_aus_v_8_2","enterprise_linux_baseos_e4s_v_8_2","enterprise_linux_baseos_tus_v_8_2","enterprise_linux_baseos_eus_v_8_4","enterprise_linux_baseos_eus_v_8_6","enterprise_linux_baseos_v_8","enterprise_linux_baseos_eus_v_9_0","enterprise_linux_baseos_v_9","enterprise_linux_crb_v_9","jboss_web_server 5"],"published":"2023-02-07","updated":"2026-09-21","sourceUpdated":"2026-09-21T05:26:33+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0286.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0286.json"},{"url":"https://access.redhat.com/security/cve/CVE-2023-0286"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2164440"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-0286"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-0286"},{"url":"https://www.openssl.org/news/secadv/20230207.txt"},{"url":"https://access.redhat.com/errata/RHSA-2023:1438"},{"url":"https://access.redhat.com/errata/RHSA-2023:1335"},{"url":"https://access.redhat.com/errata/RHSA-2024:5136"},{"url":"https://access.redhat.com/errata/RHSA-2023:3354"},{"url":"https://access.redhat.com/errata/RHSA-2023:3420"},{"url":"https://access.redhat.com/errata/RHSA-2023:5209"},{"url":"https://access.redhat.com/errata/RHSA-2024:6095"},{"url":"https://access.redhat.com/errata/RHSA-2025:7895"},{"url":"https://access.redhat.com/errata/RHSA-2023:4124"},{"url":"https://access.redhat.com/errata/RHSA-2023:4252"},{"url":"https://access.redhat.com/errata/RHSA-2023:4128"},{"url":"https://access.redhat.com/errata/RHSA-2023:2932"},{"url":"https://access.redhat.com/errata/RHSA-2023:2022"},{"url":"https://access.redhat.com/errata/RHSA-2023:1199"},{"url":"https://access.redhat.com/errata/RHSA-2023:0946"},{"url":"https://access.redhat.com/errata/RHSA-2023:2165"},{"url":"https://access.redhat.com/errata/RHSA-2025:7733"},{"url":"https://access.redhat.com/errata/RHSA-2025:7937"},{"url":"https://access.redhat.com/errata/RHSA-2023:1437"},{"url":"https://access.redhat.com/errata/RHSA-2023:1439"},{"url":"https://access.redhat.com/errata/RHSA-2023:1440"},{"url":"https://access.redhat.com/errata/RHSA-2023:1441"},{"url":"https://access.redhat.com/errata/RHSA-2023:1405"},{"url":"https://access.redhat.com/errata/RHSA-2023:3421"},{"url":"https://github.com/pyca/cryptography/security/advisories/GHSA-x4qr-2fvf-3mr5"},{"url":"https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.6.2-relnotes.txt"},{"url":"https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/018_x509.patch.sig"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2c6c9d439b484e1ba9830d8454a34fa4f80fdfe9"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2f7530077e0ef79d98718138716bc51ca0cad658"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fd2af07dc083a350c959147097003a14a5e8ac4d"},{"url":"https://github.com/pyca/cryptography"},{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003"},{"url":"https://rustsec.org/advisories/RUSTSEC-2023-0006.html"},{"url":"https://security.gentoo.org/glsa/202402-08"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.59501,"epssPercentile":0.99105,"aliases":["GHSA-x4qr-2fvf-3mr5","PYSEC-2026-800","RUSTSEC-2023-0006"],"ecosystem":"pip","ingestedAt":"2026-07-08T18:25:54.108Z","slug":"CVE-2023-0286","body":"## Overview\n\nA type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or cause a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, of which neither needs a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. In this case, this vulnerability is likely only to affect applications that have implemented their own functionality for retrieving CRLs over a network.\n\n## Vendor advisories\n\n- **RHSA-2023:1438** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 6 ELS), Red Hat Enterprise Linux Server Optional (v. 6 ELS) · released 2023-03-23 · [advisory](https://access.redhat.com/errata/RHSA-2023:1438)\n- **RHSA-2023:1335** · Red Hat · fixed in: Red Hat Enterprise Linux Client (v. 7), Red Hat Enterprise Linux Client Optional (v. 7), Red Hat Enterprise Linux ComputeNode Optional (v. 7), Red Hat Enterprise Linux Server (v. 7), Red Hat Enterprise Linux Server Optional (v. 7), Red Hat Enterprise Linux Workstation (v. 7), … · released 2023-03-20 · [advisory](https://access.redhat.com/errata/RHSA-2023:1335)\n- **RHSA-2024:5136** · Red Hat · fixed in: Red Hat Enterprise Linux Server AUS (v. 7.7), Red Hat Enterprise Linux Server Optional AUS (v. 7.7) · released 2024-08-08 · [advisory](https://access.redhat.com/errata/RHSA-2024:5136)\n- **RHSA-2023:3354** · Red Hat · fixed in: Red Hat JBoss Core Services on RHEL 7 Server, Red Hat JBoss Core Services on RHEL 8 · released 2023-06-05 · [advisory](https://access.redhat.com/errata/RHSA-2023:3354)\n- **RHSA-2023:3420** · Red Hat · fixed in: Red Hat JBoss Web Server 5.7 for RHEL 7 Server, Red Hat JBoss Web Server 5.7 for RHEL 8, Red Hat JBoss Web Server 5.7 for RHEL 9 · released 2023-06-05 · [advisory](https://access.redhat.com/errata/RHSA-2023:3420)\n- **RHSA-2023:5209** · Red Hat · fixed in: Red Hat Virtualization 4 Hypervisor for RHEL 8 · released 2023-09-19 · [advisory](https://access.redhat.com/errata/RHSA-2023:5209)\n- **RHSA-2024:6095** · Red Hat · fixed in: RHOL 5.9 for RHEL 9 · released 2024-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2024:6095)\n- **RHSA-2025:7895** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2025-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2025:7895)\n- **RHSA-2023:4124** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v. 8.2), Red Hat Enterprise Linux AppStream E4S (v. 8.2), Red Hat Enterprise Linux AppStream TUS (v. 8.2) · released 2023-07-18 · [advisory](https://access.redhat.com/errata/RHSA-2023:4124)\n- **RHSA-2023:4252** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream E4S (v.8.4), Red Hat Enterprise Linux AppStream TUS (v.8.4) · released 2023-07-25 · [advisory](https://access.redhat.com/errata/RHSA-2023:4252)\n- **RHSA-2023:4128** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.8.6) · released 2023-07-18 · [advisory](https://access.redhat.com/errata/RHSA-2023:4128)\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 7, Red Hat JBoss Web Server 3 · no fix planned: Red Hat JBoss Web Server 3, Red Hat Enterprise Linux 7 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0286.json)\n\n**openssl: X.400 address type confusion in X.509 GeneralName** — rated Important by Red Hat. Released 2023-02-07, updated 2026-09-21.\n\nAffected:\n\n- Red Hat Enterprise Linux 7\n- Red Hat JBoss Web Server 3\n\nFixed:\n\n- Red Hat Enterprise Linux Server (v. 6 ELS)\n- Red Hat Enterprise Linux Server Optional (v. 6 ELS)\n- Red Hat Enterprise Linux Client (v. 7)\n- Red Hat Enterprise Linux Client Optional (v. 7)\n- Red Hat Enterprise Linux ComputeNode Optional (v. 7)\n- Red Hat Enterprise Linux Server AUS (v. 7.7)\n- Red Hat Enterprise Linux Server (v. 7)\n- Red Hat JBoss Core Services on RHEL 7 Server\n- Red Hat JBoss Web Server 5.7 for RHEL 7 Server\n- Red Hat Enterprise Linux Server Optional AUS (v. 7.7)\n- Red Hat Enterprise Linux Server Optional (v. 7)\n- Red Hat Enterprise Linux Workstation (v. 7)\n- Red Hat Enterprise Linux Workstation Optional (v. 7)\n- Red Hat JBoss Core Services on RHEL 8\n- Red Hat JBoss Web Server 5.7 for RHEL 8\n- Red Hat Virtualization 4 Hypervisor for RHEL 8\n- Red Hat JBoss Web Server 5.7 for RHEL 9\n- RHOL 5.9 for RHEL 9\n- Red Hat Enterprise Linux AppStream (v. 8)\n- Red Hat Enterprise Linux AppStream AUS (v. 8.2)\n- Red Hat Enterprise Linux AppStream E4S (v. 8.2)\n- Red Hat Enterprise Linux AppStream TUS (v. 8.2)\n- Red Hat Enterprise Linux AppStream AUS (v.8.4)\n- Red Hat Enterprise Linux AppStream E4S (v.8.4)\n- Red Hat Enterprise Linux AppStream TUS (v.8.4)\n- Red Hat Enterprise Linux AppStream EUS (v.8.6)\n- Red Hat Enterprise Linux AppStream EUS (v.9.0)\n- Red Hat Enterprise Linux AppStream (v. 9)\n- Red Hat Enterprise Linux AppStream EUS (v.9.4)\n- Red Hat Enterprise Linux BaseOS E4S (v. 8.1)\n- Red Hat Enterprise Linux BaseOS AUS (v. 8.2)\n- Red Hat Enterprise Linux BaseOS E4S (v. 8.2)\n- Red Hat Enterprise Linux BaseOS TUS (v. 8.2)\n- Red Hat Enterprise Linux BaseOS EUS (v.8.4)\n- Red Hat Enterprise Linux BaseOS EUS (v.8.6)\n- Red Hat Enterprise Linux BaseOS (v. 8)\n- Red Hat Enterprise Linux BaseOS EUS (v.9.0)\n- Red Hat Enterprise Linux BaseOS (v. 9)\n- Red Hat Enterprise Linux CRB (v. 9)\n- Red Hat JBoss Web Server 5\n\nNo fix planned:\n\n- Red Hat JBoss Web Server 3\n- Red Hat Enterprise Linux 7\n\nNot affected:\n\n- Red Hat JBoss Core Services on RHEL 7 Server\n- Red Hat JBoss Core Services on RHEL 8\n- RHEL 8-based RHEV-H for RHEV 4 (build requirements)\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nFor the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. https://access.redhat.com/errata/RHSA-2023:1438\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nFor the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. https://access.redhat.com/errata/RHSA-2023:1335\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2024:5136\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2023-0286)\n\nAffected packages:\n\n- `cryptography >= 0.8.1, < 39.0.1`\n- `openssl-src < 111.25.0`\n- `openssl-src >= 300.0.0, < 300.0.12`\n\nPatched in:\n\n- `cryptography 39.0.1`\n- `openssl-src 111.25.0`\n- `openssl-src 300.0.12`\n\nSource: https://osv.dev/vulnerability/GHSA-x4qr-2fvf-3mr5","depth":"twilight","depthScore":53,"depthScoreParts":{"impact":40.7,"likelihood":11.9,"exploitation":0,"ransomware":0},"changes":[]}