39 ms·
Patch OpenSSL on November 1 to avoid “critical” security vulnerability
- sullivanmatt 4y agoUbuntu 22.04 & RHEL 9 are the major distros impacted. Docker images built on ubuntu:latest will also be impacted. The latest releases of Alpine/Debian/AL2 are all not impacted, they use 1.1.x lineage.
- hotcoffeebear 4y agoThat’s the reason Fedora 37 is still in beta (read that they will ship it with kernel 6.0 & gnome 43.1 as well)
- topspin 4y agoAmazon Linux 2022 Preview (the upcoming successor to Amazon Linux 2) is also using OpenSSL 3. Had to shut down one host I have using that for an ongoing project until Amazon makes another RC package update. That was, as it turns out, the only OpenSSL 3 host I'm presently dealing with.
- deleted 4y ago[deleted]
- altdataseller 4y agoWhat if you're using using the 1.0.x lineage? Does this vulnerability specifically impact you? ducks and covers
- yellow_lead 4y agoFrom the article: >If you’re using version 1.1.1, this vulnerability doesn’t affect you, but there is a 1.1.1 update coming on Tuesday as well, version 1.1.1s, which you’re still going to need to update to anyway so you might as well schedule some time on Tuesday, too.
- altdataseller 4y agoYep, so I assume this applies to 1.0.x as well?
- yellow_lead 4y agoSorry, I misunderstood your question. But it looks like this will only affect users running 3.0.0 - 3.0.6.
- saurik 4y agoPreviously: https://news.ycombinator.com/item?id=33330752 https://news.ycombinator.com/item?id=33330752 https://news.ycombinator.com/item?id=33364183 https://news.ycombinator.com/item?id=33364183
- 29athrowaway 4y ago
- RealStickman_ 4y agoGet started then. We can't use something with no track record nor releases published in production systems.
- 29athrowaway 4y agoThen rewrite in Ada or whatever. Ada has been around for a while and has been used in important projects.
- pyuser583 4y agoIs Ada memory safe? I don’t think it is.
- yjftsjthsd-h 4y agohttps://www.reddit.com/r/ada/comments/mme3jk/is_ada_memory_safe/ https://www.reddit.com/r/ada/comments/mme3jk/is_ada_memory_s... seems to think so, although unfortunately I'm not qualified to evaluate it (so take this with a medium-large grain of salt...)
- 29athrowaway 4y agoIt is still a significant upgrade in terms of safety over C.
- pyuser583 4y agoThe main argument against Ada is you can achieve a higher level of safety/convenience using C++ frameworks and code analysis tools.
- 29athrowaway 4y ago
- Gigachad 4y agoHow many times does this have to happen before we start rejecting components written in unsafe languages?
- bradleyjg 4y agoYou first. What browser and OS are you posting from?
- throwawaymaths 4y agoIf your server is in Erlang, it's probably dodged this (Erlang dodged heart bleed because it only uses ssl libs for cryptographic primitives)
- speedgoose 4y agoNot OS or browser but my SSH servers use Teleport and my HTTPS servers use Traefik or Caddy. Caddy, Traefik, and Teleport are written in Golang and not using OpenSSL. It’s a start.
- timdoug 4y agoI adore Go, but it seems to be impacted too: https://groups.google.com/g/golang-announce/c/dRtDK7WS78g https://groups.google.com/g/golang-announce/c/dRtDK7WS78g
- woodruffw 4y agoThis is almost certainly a different bug. I don't believe Go's standard library uses OpenSSL.
- timdoug 4y agoYou’re right re: implementation —- I’m drawing a conclusion solely from the coordinated disclosure that it’s a similar crypto/TLS issue. If the Go issues were distinct I’d imagine they’d choose a different day to disclose/release?
- amatecha 4y ago
- eastbound 4y agoNovember 1st is a bank holiday in France, so a lot of sysadmins won’t be happy and systems will be vulnerable.
- Xenoamorphous 4y agoSpain, too.
- fulafel 4y agoThis is most likely but another possibility is that it was coordinated to happen on a bank holiday so systems can be dated with less impact from service outages.
- midasuni 4y agoIn that case why not release about 0700UTC on a Saturday, pretty much everywhere has the weekend going either then or starting within a few hours
- solatic 4y agoAlso an election day in Israel, which is a bank holiday.
- CodeWriter23 4y agoPeople don’t work “On Call” any more? That’s news to me.
- mmwelt 4y ago> And by widely leveraged, I mean almost completely ubiquitous, if you’re using HTTPS, chances are you’re using OpenSSL. Almost everyone is. This is probably a bit of an exaggeration. There are quite a few other SSL implementations that actually are also "widely leveraged"[1]. In particular, LibreSSL was forked and cleaned up after Heartbleed. Google uses BoringSSL. GnuTLS is widely used and unrelated to OpenSSL. [1] https://en.wikipedia.org/wiki/Comparison_of_TLS_implementations https://en.wikipedia.org/wiki/Comparison_of_TLS_implementati...
- woodruffw 4y agoIs GnuTLS widely used? People bring it up, but I've never actually seen it in a codebase (and I deal with a lot of x509 + PKCS code). I've seen more wolfSSL and mbedTLS than GnuTLS.
- SSLy 4y agowidely? depends on your viewpoint, but there are quite few consumers (look at the right column) https://archlinux.org/packages/core/x86_64/gnutls/ https://archlinux.org/packages/core/x86_64/gnutls/
- shandor 4y agoHow is wolfSSL/SSH? I have come across them a couple of times, but not having anyone/anything ”famous” behind them when compared to GNUtls or mbedtls always made me somewhat wary.
- saghm 4y agoFrom looking at my currently installed packages, there are quite a few that depend on gnutls: ffmpeg, gnupg, libcups, vlc, and wget look like the ones that would be most well known. It's possible that they only use it as an option, but normally I'd expect it to only be an optional dependency if that were the case. I haven't looked at any of their codebases though, so no idea what they use it for!
- Conan_Kudo 4y agoOne lesser known common user of GnuTLS is GNOME. Pretty much the entire GNOME ecosystem uses it.
- fh973 4y agoCouldn't they be a bit more specific? No software uses all of openssl, there is software that uses it for other things than server-side TLS.
- fulafel 4y agoFor example, OpenSSH.
- bondant 4y agoDoes OpenSSH use OpenSSL? I thought they migrated to LibreSSL.
- fulafel 4y agoThe Ubuntu 22.04 LTS openssh-server package seems to depend on libss3 which is built from OpenSSL: https://packages.ubuntu.com/jammy/openssh-server https://packages.ubuntu.com/jammy/openssh-server -> https://packages.ubuntu.com/jammy/libssl3 https://packages.ubuntu.com/jammy/libssl3 -> https://packages.ubuntu.com/source/jammy/openssl https://packages.ubuntu.com/source/jammy/openssl Apparently there are some problems with LibreSSL on Linux: https://lwn.net/Articles/841664/ https://lwn.net/Articles/841664/ (Also, do we know that LibreSSL is unaffected?)
- Lex-2008 4y agoThe globalsign atricle says: > If you’re using version 1.1.1, this vulnerability doesn’t affect you AFAIK, LibreSSL forked even before that - when OpenSSL was version 1.0 or 0.9 even. So likely not affected - unless a similar issue appeared there after the fork.
- fulafel 4y agoParallel forks sometimes keep incorporating quite a lot of changes from each other, in the *BSD fork tradition. I'd also guess that LibreSSL is not affected but it's not a foregone conclusion. In the previous OpenSSH vs OpenSSL 3 bug it went like this: > The issue has been identified in OpenSSL version 3.0.4, which was released on June 21, 2022, and impacts x64 systems with the AVX-512 instruction set. OpenSSL 1.1.1 as well as OpenSSL forks BoringSSL and LibreSSL are not affected. (https://thehackernews.com/2022/06/openssh-to-release-security-patch-for.html https://thehackernews.com/2022/06/openssh-to-release-securit...)
- s-macke 4y agoWhen I execute an ldd at /usr/bin/ssh I get libssl.so.10 => /lib64/libssl.so.10 libssl3.so => /lib64/libssl3.so libnss3.so => /lib64/libnss3.so What puzzles me is that I am using libssl.so.10 and libssl3.so at the same time. libssl3.so belongs to the nss package and not to the openssl package. Am I affected?
- xorcist 4y agoIt is very unlikely that this affects OpenSSH regardless. Only the cryptographic primitives are used from OpenSSL, and none of the complexity of the SSL functions. The cryptographic functions themselves are small and extremely well tested.
- fulafel 4y agoOpenSSH (or commonly used variants thereof?) supports X.509 certificates, would they really reimplement that can of worms instead of using already linked libssl functions? Especially since on OpenSSH's home platform libssl is LibreSSL which they consider safer than OpenSSL. Also, there already was one OpenSSL 3 crypto primitive caused vuln or at least security relevant bug in OpenSSH this year: https://thehackernews.com/2022/06/openssh-to-release-security-patch-for.html https://thehackernews.com/2022/06/openssh-to-release-securit...
- fulafel 4y agoCorrecting myself: in the ssh-keygen manpage it says that the cert format is not X.509: Note that OpenSSH certificates are a different, and much simpler, format to the X.509 certificates used in ssl(8).
- s-macke 4y agoI took ssh only as an example as curl has the same dependency. But thanks to @Beltalowda it is obvious, that the lib64/openssl3 does not belong to openssl.
- Beltalowda 4y agoThe libssl3.so shared object from NSS just has a similar name. This is very confusing, but NSS has been around for a long time, before OpenSSL became the de-facto standard (sort-of), and certainly long before OpenSSL 3, so now we're "stuck" with this confusion.
- jbverschoor 4y agoWhat's the 'best' way to find out if there are binaries in which libssl is statically linked?
- g_p 4y agoIf you're using distro packages, their own "packaging policy" should offer some level of assurance via policy about static linking (since as far as I know, all major distros dynamically link, to make this kind of bugfix easier). If you're talking non distro packages (proprietary, or anything built manually from PPA or equivalent, or binaries dumped inside containers), this won't help.
- jbverschoor 4y agoSure, but there might also be binaries outside the distro which link things statically, because makes distribution easier. This is one of the "benefits" of go, where afaik many things are linked statically. I'm currently playing around with grepping some function-names to find out if something uses libssl, and then check if ldd to see if libssl is loaded dynamically or not.
- g_p 4y agoIndeed - this is one of the positives of Go, as all the dependencies get linked statically, giving nice portable "single binary" solutions. Grepping function names seems a reasonable approach, as long as you're not trying to detect something that is obfuscating its use of libssl (i.e. by mangling strings together). It appears if you strip a binary, any definitive information about the libraries linked in statically is lost, beyond function names and argument combinations. I believe there are tools in IDA and similar, which can match functions based on their input argument types and name. That might help you match to a rough version of the upstream library, if parameters changed.
- tremon 4y agoUnsure why people keep referring to static linking as a positive in this thread? Downstream consumers of statically-linked binaries have no practical way to scan their systems for known-vulnerable versions of libraries, that seems a profoundly negative consequence to me.
- frankjr 4y agoThis is supposedly the commit which fixes the bug https://github.com/openssl/openssl/commit/3df6aed7826640d944da382f78af5ab87ea790db https://github.com/openssl/openssl/commit/3df6aed7826640d944...
- ancarda 4y agoI don't know a lot about C or the internals of OpenSSL, but going by the commit message, does this mean we should disable TLSv1.3 until we've had a chance to patch OpenSSL? Edit: Actually, reading through the code a few times, maybe TLSv1.2 should be disabled? I really wish we had some way to protect ourselves until the patch is widely available.
- ylk 4y agoSee the other comments for why the parent is wrong. > I really wish we had some way to protect ourselves until the patch is widely available. I would hope/expect that the OpenSSL project has no indication that this vulnerability is used in the wild. And that is probably why they preferred announcing a patch date instead of releasing a fix right away. (But I don’t know their policies, so this is just speculation.) That would mean that you don’t really need to do anything you shouldn’t have already been doing prior to this announcement to protect yourself until the patch is out. Unless the vulnerability is easy to find — in which case we’d already hear about exploitation attempts, so I don’t think it is — worrying about this is as useful as worrying about the other critical yet-to-be-found vulnerabilities in the software you use (which most certainly exist).
- colmmacc 4y agoThe relevant commits and pull requests are confidential and per OpenSSL's normal operating procedures are only available on an embargoed private fork to embargo participants.
- Ayesh 4y agoI highly doubt it. I have done security releases before (not in OpenSSL), and the first line we have there is that don't push upstream in the flashiest text possible. In OpenSSL's case, they might share it with other major OSs beforehand (because many software statically link to OpenSSL), but there is always a secure channel in place to make sure the patches/commits are not leaked. In the unfortunate event that the commits were pushed to a public repository, the most sensible thing to do is to just release the tagged release with the security announcement anyway.
- rascul 4y agoThis is basically useless without identifying the vulnerability.
- detaro 4y agoIt's not useless, and if it identified the vulnerability it'd massively increase the risk of it being used before patch release.
- rascul 4y agoIt's useless because I don't know if I need to care. Vulnerabilities in openssl are nothing new so as far as I know this is just par for the course, and I get nothing out of it as of yet.
- detaro 4y ago... and an announcement like this is a fairly strong message of "assume you need to care"
- deleted 4y ago[deleted]
- rascul 4y agoI'm not going to assume anything in regards to a future release I have no details about.
- deleted 4y ago[deleted]
- iamtedd 4y agoSo what do you propose is the alternative? Not tell you about the vulnerability at all until a patch is released? Publish all the details about the vulnerability before a patch is available? Seriously, what are you complaining about?
- jrootabega 4y agoHere's the official place where these are announced, if you feel a little uneasy getting urgent security advisories from tweets and blogs: https://mta.openssl.org/mailman/listinfo/openssl-announce https://mta.openssl.org/mailman/listinfo/openssl-announce
- rav 4y agoHere's a direct link to the 3.0.7 announcement in the archive: https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html https://mta.openssl.org/pipermail/openssl-announce/2022-Octo...
- _hyn3 4y agoYour point stands, but FWIW, this is actually Globalsign GMO[0], one of the largest TLS certificate authorities (CA's), so certainly they have a vested interest in making sure OpenSSL is secure. (Globalsign also partnered with CloudFlare for TLS certificates[1]) 0. https://en.wikipedia.org/wiki/GlobalSign https://en.wikipedia.org/wiki/GlobalSign 1. https://techcrunch.com/2012/11/01/cloudflare-globalsign-make-ssl-faster/ https://techcrunch.com/2012/11/01/cloudflare-globalsign-make...
- jrootabega 4y agoI don't think the post is inaccurate or the authors untrustworthy, but I don't think it's a good idea to rely on their blog to get OpenSSL alerts, especially when there is an official, high signal-to-noise, alternative. If someone reads this HN submission and wants to make sure they get alerted about the next critical vulnerability, they should subscribe.
- greggsy 4y agoIt’s not practical to subscribe to security feeds for every OSS project. Keeping in touch with the tech community is a valid alternative, in combination with patching best practice.
- 4y ago
- sylware 4y agoDoes libressl have this vulnerability?
- Genghis_9000 4y agowhen will browsers learn and just replace ssl/tls with one line of code to verify that the public key portion of the URL matches the session established by the website? C is only a hundredth of the problem here (that 100th is still big). its ironic that this news was brought to us by a scammer's corporate blog
- creatonez 4y ago> when will browsers learn and just replace ssl/tls with one line of code to verify that the public key portion of the URL matches the session established by the website? Can you elaborate?
- charcircuit 4y agoDoes anyone have a fix for this so I'm not vulnerable for the next week?