Description
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).
Published: 2022-07-05
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-3325-1 openssl security update
Debian DSA Debian DSA DSA-5343-1 openssl security update
EUVD EUVD EUVD-2022-6221 AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).
Github GHSA Github GHSA GHSA-3wx7-46ch-7rq2 AES OCB fails to encrypt some bytes
Ubuntu USN Ubuntu USN USN-5502-1 OpenSSL vulnerability
Ubuntu USN Ubuntu USN USN-6457-1 Node.js vulnerabilities
History

Thu, 26 Feb 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Netapp active Iq Unified Manager For Vmware Vsphere
Netapp brocade Fabric Operating System Firmware
Netapp hci Baseboard Management Controller
Netapp oncommand Insight
Netapp ontap Antivirus Connector
Netapp ontap Select Deploy Administration Utility
Netapp smi-s Provider
Netapp snapcenter
CPEs cpe:2.3:a:netapp:active_iq_unified_manager_for_vmware_vsphere:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:hci_baseboard_management_controller:h300s:*:*:*:*:*:*:*
cpe:2.3:a:netapp:hci_baseboard_management_controller:h410c:*:*:*:*:*:*:*
cpe:2.3:a:netapp:hci_baseboard_management_controller:h410s:*:*:*:*:*:*:*
cpe:2.3:a:netapp:hci_baseboard_management_controller:h500s:*:*:*:*:*:*:*
cpe:2.3:a:netapp:hci_baseboard_management_controller:h700s:*:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_insight:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_antivirus_connector:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:smi-s_provider:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:snapcenter:*:*:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:3.0.0:*:*:*:*:*:*:*
cpe:2.3:o:netapp:brocade_fabric_operating_system_firmware:*:*:*:*:*:*:*:*
Vendors & Products Netapp active Iq Unified Manager For Vmware Vsphere
Netapp brocade Fabric Operating System Firmware
Netapp hci Baseboard Management Controller
Netapp oncommand Insight
Netapp ontap Antivirus Connector
Netapp ontap Select Deploy Administration Utility
Netapp smi-s Provider
Netapp snapcenter
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Debian Debian Linux
Fedoraproject Fedora
Netapp Active Iq Unified Manager Active Iq Unified Manager For Vmware Vsphere Brocade Fabric Operating System Firmware Clustered Data Ontap Antivirus Connector H300s Firmware H410c H410c Firmware H410s H410s Firmware H500s H500s Firmware H700s H700s Firmware Hci Baseboard Management Controller Oncommand Insight Ontap Antivirus Connector Ontap Select Deploy Administration Utility Smi-s Provider Snapcenter
Openssl Openssl
Redhat Enterprise Linux
Siemens Sinec Ins
cve-icon MITRE

Status: PUBLISHED

Assigner: openssl

Published:

Updated: 2024-09-17T01:06:49.390Z

Reserved: 2022-06-16T00:00:00.000Z

Link: CVE-2022-2097

cve-icon Vulnrichment

Updated: 2024-08-03T00:24:44.189Z

cve-icon NVD

Status : Modified

Published: 2022-07-05T11:15:08.340

Modified: 2024-11-21T07:00:18.757

Link: CVE-2022-2097

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-07-05T00:00:00Z

Links: CVE-2022-2097 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses