Asymmetric denial of service - ReDoS In OVMF
Description
A vulnerability was found in the Diffie-Hellman Ephemeral (DHE) Key Agreement Protocol, where a malicious client can exploit the server's public key validation process. By forcing the server to use DHE and validating the order of public keys, the client can trigger expensive server-side modular exponentiation calculations. This issue results in asymmetric resource consumption, potentially leading to a denial of service (DoS) attack by overwhelming the server with computationally intensive operations.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component |
|---|---|
rpm rhel8 | |
rpm rhel9 | |
rpm rhel7 | |
rpm rhel8 | |
rpm rhel10 | |
rpm rhel6 | |
rpm rhel7 | |
rpm rhel8 | |
rpm rhel9 |
Aliases