AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).
Project Subscriptions
| Vendors | Products |
|---|---|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Netapp
Subscribe
|
Active Iq Unified Manager
Subscribe
Active Iq Unified Manager For Vmware Vsphere
Subscribe
Brocade Fabric Operating System Firmware
Subscribe
Clustered Data Ontap Antivirus Connector
Subscribe
H300s Firmware
Subscribe
H410c
Subscribe
H410c Firmware
Subscribe
H410s
Subscribe
H410s Firmware
Subscribe
H500s
Subscribe
H500s Firmware
Subscribe
H700s
Subscribe
H700s Firmware
Subscribe
Hci Baseboard Management Controller
Subscribe
Oncommand Insight
Subscribe
Ontap Antivirus Connector
Subscribe
Ontap Select Deploy Administration Utility
Subscribe
Smi-s Provider
Subscribe
Snapcenter
Subscribe
|
|
Openssl
Subscribe
|
Openssl
Subscribe
|
|
Redhat
Subscribe
|
Enterprise Linux
Subscribe
|
|
Siemens
Subscribe
|
Sinec Ins
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3325-1 | openssl security update |
Debian DSA |
DSA-5343-1 | openssl security update |
EUVD |
EUVD-2022-6221 | AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p). |
Github GHSA |
GHSA-3wx7-46ch-7rq2 | AES OCB fails to encrypt some bytes |
Ubuntu USN |
USN-5502-1 | OpenSSL vulnerability |
Ubuntu USN |
USN-6457-1 | Node.js vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 26 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp active Iq Unified Manager For Vmware Vsphere
Netapp brocade Fabric Operating System Firmware Netapp hci Baseboard Management Controller Netapp oncommand Insight Netapp ontap Antivirus Connector Netapp ontap Select Deploy Administration Utility Netapp smi-s Provider Netapp snapcenter |
|
| CPEs | cpe:2.3:a:netapp:active_iq_unified_manager_for_vmware_vsphere:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:hci_baseboard_management_controller:h300s:*:*:*:*:*:*:* cpe:2.3:a:netapp:hci_baseboard_management_controller:h410c:*:*:*:*:*:*:* cpe:2.3:a:netapp:hci_baseboard_management_controller:h410s:*:*:*:*:*:*:* cpe:2.3:a:netapp:hci_baseboard_management_controller:h500s:*:*:*:*:*:*:* cpe:2.3:a:netapp:hci_baseboard_management_controller:h700s:*:*:*:*:*:*:* cpe:2.3:a:netapp:oncommand_insight:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap_antivirus_connector:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:smi-s_provider:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:snapcenter:*:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:1.1.1:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:3.0.0:*:*:*:*:*:*:* cpe:2.3:o:netapp:brocade_fabric_operating_system_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netapp active Iq Unified Manager For Vmware Vsphere
Netapp brocade Fabric Operating System Firmware Netapp hci Baseboard Management Controller Netapp oncommand Insight Netapp ontap Antivirus Connector Netapp ontap Select Deploy Administration Utility Netapp smi-s Provider Netapp snapcenter |
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: openssl
Published:
Updated: 2024-09-17T01:06:49.390Z
Reserved: 2022-06-16T00:00:00.000Z
Link: CVE-2022-2097
Updated: 2024-08-03T00:24:44.189Z
Status : Modified
Published: 2022-07-05T11:15:08.340
Modified: 2024-11-21T07:00:18.757
Link: CVE-2022-2097
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN