← Back to CVE List
Vulnerability Intelligence Report
RSA implementation bug in AVX512IFMA instructions

CVE-2022-2274

The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation. SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86_64 architecture are affected by this issue.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:36.51%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
OpenSSL OpenSSL Affects OpenSSL 3.0.4 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
36.513%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityOpenSSL Software Foundation · Vendor · USA
Reserved2022-06-30T00:00:00
Published2022-07-01T07:30:17
Patch Date2022-06-09
Last Updated2024-09-17T00:20:40

LINK COPIED TO CLIPBOARD