sk182320 - Check Point Response to CVE-2024-2511 - OpenSSL unbounded memory growth with session handling in TLSv1.3

Check Point Response to CVE-2024-2511 - OpenSSL unbounded memory growth with session handling in TLSv1.3

Please read this important update from Check Point.

Security Alert:

Symptoms

This vulnerability allows for initiating a Denial of Service (DoS) attack by triggering unbounded memory growth when processing TLSv1.3 sessions with certain non-default TLS server configurations. This configuration is only activated in the event of an error while creating a TLS session.

The severity of this CVE is low, and the likelihood of it occurring is rare.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

Note: The "cpopenssl version" command would still show "OpenSSL 1.1.1w" because the fix for CVE-2024-2511 is a patch in the Check Point code and not an update for the OpenSSL package.

Article Properties