CVE-2023-0216

Aliases:GHSA-29xx-hcv2-c4cpRUSTSEC-2023-0011ALPINE-CVE-2023-0216DEBIAN-CVE-2023-0216CGA-c87q-rfqp-qcr5CGA-hh5v-rr6v-w7p9CGA-fhv3-xgpv-q7h3CGA-j754-q65q-p9hwCGA-r6hc-5xvm-3qjpCGA-rw62-6m83-xq8p
Modified
Published: 08 Feb 2023, 19:03
Last modified:04 Nov 2025, 19:14

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
1.85% LOW
2% probability +1.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Feb 2023, 19:03
Published
Vulnerability first disclosed
04 Nov 2025, 19:14
Last Modified
Vulnerability information updated

Description

An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service attack. The TLS implementation in OpenSSL does not call this function however third party applications might call these functions on untrusted data.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 1.85% Percentile: 78%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • alpineopenssl

    ≥ 3.0.0, < 3.0.8-r0 | ≥ 3.0.0, < 3.0.8-r0 | ≥ 3.0.0, < 3.0.8-r0 | ≥ 3.0.0, < 3.0.8-r0 | ≥ 3.0.0, < 3.0.8-r0 | ≥ 3.0.0, < 3.0.8-r0 | ≥ 3.0.0, < 3.0.8-r0 | ≥ 3.0.0, < 3.0.8-r0

  • alpineopenssl3

    < 3.0.8-r0 | < 3.0.8-r0

  • chainguardopenssl

    < 3.1.0-r0

  • chainguardopenssl-provider-fips

    < 3.0.8-r0

  • chainguardruby-3.1

    < 0

  • wolfiopenssl

    < 3.1.0-r0

  • wolfiruby-3.1

    < 0

  • Crates.Ioopenssl-src

    ≥ 300.0.0, < 300.0.12

  • debianopenssl

    < 3.0.8-1 | < 3.0.8-1 | < 3.0.8-1

  • opensslopenssl

    ≥ 3.0.0, < 3.0.8 | ≥ 3.0.0, ≤ 3.0.7

  • stormshieldstormshield_management_center

    < 3.3.3

References (10)