FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

OpenSSL -- Vector register corruption on PowerPC

Affected packages
openssl < 3.0.12_2,1
openssl-quictls < 3.0.12_2
openssl31 < 3.1.4_2
openssl31-quictls < 3.1.4_2
openssl32 < 3.2.0_1

Details

VuXML ID 8337251b-b07b-11ee-b0d7-84a93843eb75
Discovery 2024-01-09
Entry 2024-01-11

SO-AND-SO reports:

The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications running on PowerPC CPU based platforms if the CPU provides vector instructions.

References

CVE Name CVE-2023-6129
URL https://www.openssl.org/news/secadv/20240109.txt