CVE-2022-4087
Linux Red Hat vulnerability analysis and mitigation

Overview

A vulnerability was discovered in iPXE's TLS implementation, specifically in the tls_new_ciphertext function within src/net/tls.c. The vulnerability was assigned CVE-2022-4087 and relates to how the system handles block padding in TLS communications (GitHub Commit).

Technical details

The vulnerability exists in the TLS implementation where invalid block padding was not properly handled, potentially leading to timing attacks. The issue specifically occurs in the tls_new_ciphertext function where the system previously returned immediately upon detecting invalid padding. The fix involves treating invalid block padding as zero-length padding to defer the failure until after computing the incorrect MAC, thereby hardening against padding oracle attacks (GitHub Commit).

Mitigation and workarounds

The vulnerability has been patched by modifying the handling of invalid block padding. Instead of immediately returning an error when invalid padding is detected, the system now treats it as zero-length padding and continues processing. This change helps prevent timing-based attacks by ensuring consistent processing time regardless of padding validity (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Red Hat vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23950HIGH8.8
  • GrafanaGrafana
  • nodejs:20::nodejs-packaging
NoNoJan 20, 2026
CVE-2026-23884HIGH7.7
  • Linux DebianLinux Debian
  • freerdp3
NoNoJan 19, 2026
CVE-2026-23883HIGH7.7
  • Linux DebianLinux Debian
  • freerdp3
NoNoJan 19, 2026
CVE-2026-23534HIGH7.7
  • Linux DebianLinux Debian
  • freerdp-devel
NoNoJan 19, 2026
CVE-2026-23732MEDIUM5.5
  • Linux DebianLinux Debian
  • freerdp-libs
NoNoJan 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management