Database/Kernel, userspace & hypervisor
wolfSSL: trusted-peer matching ignores the public key, so a forged CA clone verifies
Impact
MatchTrustedPeer compares certificates without considering the public key, so a certificate that clones a loaded CA's identifying fields passes verification even though it carries an attacker's key. A malicious (D)TLS server can therefore bypass client authentication once it knows which CAs the client accepts, and the mirror case breaks mutual TLS where the client can learn the server's loaded CAs. Affected builds are those with WOLFSSL_TRUST_PEER_CERT that load CAs via wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert(); with OPENSSL_COMPATIBLE_DEFAULTS also defined the exposure widens to all CA loading, and wolfSSL notes both macros are set in autoconf builds such as nginx, haproxy, stunnel, wpa_supplicant, apache httpd, hitch, bind, rsyslog, ffmpeg and distro builds. Where wolfSSL backs mTLS between fleet components, that is an authentication bypass on links an operator believes are mutually authenticated.
Who can reach it
A network attacker able to act as the (D)TLS peer - typically an on-path or otherwise reachable server - who knows which CA certificates the victim loaded. No authentication needed (PR:N); the knowledge requirement is what makes attack requirements present (AT:P).
What to do
Update to the latest wolfSSL or apply the upstream fix commit (22bcd51), then rebuild and restart every service linked against it - a library update plus a restart of each dependent daemon, not a node reboot. If you cannot update, wolfSSL's own mitigation is to build with --disable-openssl-compatible-defaults and stop loading CAs through wolfSSL_CTX_trust_peer_cert()/wolfSSL_trust_peer_cert(). Note that distro-packaged nginx/haproxy/bind builds may need to be rebuilt, not just restarted.
References
Related entries
- Xen PCI passthrough on Intel VT-d chipsets without interrupt remapping: The founding GPU-passthrough escape. A guestCVE-2011-1898 · Xen PCI passthrough on Intel VT-d chipsets without interrupt remappingHigh
- Xen libxl (xenlight) PCI passthrough device setup: The toolstack hands a bus-mastering-capable PCI device to an HVMCVE-2013-4329 · Xen libxl (xenlight) PCI passthrough device setupHigh
- Xen Intel VT-d IOMMU page-table handling for PCI passthrough: An inverted boolean means Xen clears a present IOMMUCVE-2013-6375 · Xen Intel VT-d IOMMU page-table handling for PCI passthroughHigh
- QEMU xen_pt PCI passthrough config-space mediation (Xen 3.3.x-4.5.x): The device model failed to mediate guest writesCVE-2015-4106 · QEMU xen_pt PCI passthrough config-space mediation (Xen 3.3.x-4.5.x)High
- KVM (AMD SEV-ES): Out-of-bounds read/write in sev_es_string_io() - malicious SEV-ES guest corrupts host memoryCVE-2021-4093 · KVM (AMD SEV-ES)High
- VMware ESXi / Workstation / Fusion: Heap out-of-bounds write in the USB 2.0 EHCI controllerCVE-2022-31705 · VMware ESXi / Workstation / FusionHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.