CVE-2022-38153
NixOS vulnerability analysis and mitigation

Overview

CVE-2022-38153 affects wolfSSL version 5.3.0 when --enable-session-ticket is used. The vulnerability allows man-in-the-middle attackers or malicious servers to crash TLS 1.2 clients during a handshake. The issue was discovered in August 2022 and has a CVSS score of 5.9 (MEDIUM) (NVD, WolfSSL).

Technical details

If an attacker injects a large ticket (more than 256 bytes) into a NewSessionTicket message in a TLS 1.2 handshake, and the client has a non-empty session cache, the session cache frees a pointer that points to unallocated memory, causing the client to crash with a "free(): invalid pointer" message. The bug exists in the AddSessionToCache function. The vulnerability is also likely exploitable during TLS 1.3 handshakes between a client and a malicious server, though it cannot be exploited as a man-in-the-middle attack in TLS 1.3 (Trail of Bits).

Impact

The vulnerability results in a denial of service (DoS) condition by causing the client to crash. Approximately 30 cached sessions are required to reliably trigger the crash, as the bug depends on the hash of the session ID and whether the current cache bucket already contains a previous session (Trail of Bits).

Mitigation and workarounds

The vulnerability was fixed in wolfSSL version 5.5.0. Users running version 5.3.0 with --enable-session-ticket compiled in should update their version of wolfSSL. The fix ensures proper validation of ticket sizes and memory handling in the session cache (WolfSSL).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48606HIGH7.8
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48625HIGH7
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48608MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48569MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-65799MEDIUM4.3
  • NixOSNixOS
  • memos
NoYesDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management