Vulnerability record · CVE-2022-2274 · published 1 July 2022
CVE-2022-2274: OpenSSL 3.0.4 RSA AVX512IFMA memory corruption
OOpenssl · Openssl
OpenSSL 3.0.4 introduced a bug in the RSA implementation for X86_64 CPUs supporting AVX512IFMA instructions, causing 2048-bit private key operations to be incorrect and to corrupt memory during computation. Because this affects TLS and other servers performing RSA private key operations, it can lead to remote code execution on affected hosts.
Description
The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation. SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86_64 architecture are affected by this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and potential remote code execution, though exploitation is not confirmed in KEV.
What it is
OpenSSL 3.0.4 introduced a bug in the RSA implementation for X86_64 CPUs supporting AVX512IFMA instructions, causing 2048-bit private key operations to be incorrect and to corrupt memory during computation. Because this affects TLS and other servers performing RSA private key operations, it can lead to remote code execution on affected hosts.
Impact
An attacker may achieve remote code execution on the machine performing the RSA computation, with full loss of confidentiality, integrity and availability per the CVSS vector.
Attack surface
Reachable over the network (AV:N) with no privileges or user interaction required (PR:N/UI:N); any service that performs 2048-bit RSA private key operations on an affected CPU is exposed.
Exploitation
Not listed in CISA KEV and no ransomware use documented; EPSS is high (0.457, 98.7th percentile) and one reference is tagged Exploit, but no confirmed in-the-wild exploitation is stated.
What to do
- Upgrade OpenSSL to a version after 3.0.4 that contains the fix commit 4d8a88c134df634ba610ff8db1eb8478ac5fd345.
- If immediate upgrade is not possible, avoid running 2048-bit RSA private key operations on X86_64 hosts with AVX512IFMA, or use ECC keys instead.
- Apply vendor advisories for affected NetApp products (SnapCenter and H-series firmware) per ntap-20220715-0010.
- Inventory OpenSSL 3.0.4 deployments and confirm whether host CPUs advertise AVX512IFMA.
- Monitor for crashes or unexpected behavior in TLS/RSA services as an indicator of the memory corruption.
Detection
- Identify hosts running OpenSSL 3.0.4 via package inventory or version scanning.
- Check CPU flags for avx512ifma on systems performing RSA private key operations.
- Monitor TLS/RSA service logs and crash dumps for memory corruption or abnormal terminations.
- Watch for unexpected process crashes or restarts in services using 2048-bit RSA keys.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=4d8a88c134df634ba610ff8db1eb8478ac5fd345 | |
| https://github.com/openssl/openssl/issues/18625 | ExploitIssue TrackingThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20220715-0010/ | Third Party Advisory |
| https://www.openssl.org/news/secadv/20220705.txt | Vendor Advisory |
| https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=4d8a88c134df634ba610ff8db1eb8478ac5fd345 | |
| https://github.com/openssl/openssl/issues/18625 | ExploitIssue TrackingThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20220715-0010/ | Third Party Advisory |
| https://www.openssl.org/news/secadv/20220705.txt | Vendor Advisory |
Track CVE-2022-2274 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-2274), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.