CVE-2022-3996

X.509 Policy Constraints Double Locking

If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function. Update (31 March 2023): The description of the policy processing enablement was corrected based on CVE-2023-0466.


We have discovered 16,092 live websites that are affected by CVE-2022-3996.

Test my site




Affected Software

Product  OpenSSL
Category Web Server Extensions
Vulnerable Domains16,092 live websites (2.40% of OpenSSL install base)
Vulnerable Versions
  • from 3 through 3.0.7
Vulnerable Versions Count7 versions ( 17.50% of all versions)


Common Weakness Enumeration

CWE-667 Improper Locking



Details

  • Published - Dec 13, 2022
  • Updated - Aug 3, 2024

Credits

  • Polar Bear (finder)
  • Paul Dale (remediation developer)

CVE-2022-3996 usage by Country

United States3,623 websites



France2,345 websites
Germany1,486 websites
Japan1,317 websites
Canada848 websites
GB774 websites
Finland688 websites
Netherlands523 websites
Italy404 websites
Hungary397 websites

CVE-2022-3996 usage by TLD

.com5,684 websites
.org685 websites
.edu652 websites
.net643 websites
.ca638 websites
.fi534 websites
.jp534 websites
.fr489 websites
.de439 websites
.co.uk422 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-3996

Top websites that are affected by CVE-2022-3996. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States*,***
***.edu United States**,***
******.org Singapore**,***
********.org France**,***
********.com United States**,***
*******.net Japan**,***
******.****.edu United States**,***
************************.com United States**,***
***.com United States**,***
******.com United States**,***
See full domain list

FAQ

CVE-2022-3996 is Improper Locking in OpenSSL
A total of 16,092 websites have been identified as vulnerable to CVE-2022-3996, discovered through global website indexing conducted by WebTechSurvey.
OpenSSL is susceptible to CVE-2022-3996 vulnerability.
OpenSSL versions before, and including, 3.0.7 are vulnerable to CVE-2022-3996.