CVE-2023-6129
MySQL vulnerability analysis and mitigation

Overview

The POLY1305 MAC (message authentication code) implementation in OpenSSL contains a vulnerability (CVE-2023-6129) affecting PowerPC CPU based platforms with vector instructions. The vulnerability was discovered on October 9th, 2023 and affects OpenSSL versions 3.0.0 to 3.0.12, 3.1.0 to 3.1.4, and 3.2.0. The FIPS provider is not affected as it does not implement the POLY1305 MAC algorithm (OpenSSL Advisory).

Technical details

The vulnerability occurs because the POLY1305 MAC implementation for PowerPC CPUs restores vector registers in a different order than they are saved, leading to corruption of some vector register contents when returning to the caller. This issue only affects newer PowerPC processors that support PowerISA 2.07 instructions. The POLY1305 MAC algorithm is primarily used as part of the CHACHA20-POLY1305 AEAD algorithm, commonly used in TLS 1.2 and 1.3. The vulnerability has been assigned a CVSS v3.1 base score of 6.5 MEDIUM (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) (NVD).

Impact

The consequences of this vulnerability can vary depending on the application. If the application doesn't depend on non-volatile XMM register contents, there may be no impact. However, in worst-case scenarios, an attacker could potentially gain complete control of the application process. The most likely outcomes are incorrect calculation results or crashes leading to denial of service. For TLS server applications using OpenSSL, a malicious client can influence whether the vulnerable CHACHA20-POLY1305 AEAD cipher is used (OpenSSL Advisory).

Exploitability

The vulnerability requires an attacker to have network access and the ability to influence whether the POLY1305 MAC algorithm is used. The attack complexity is considered high, and no authentication is required. While the vulnerability is publicly known, there are currently no known instances of this vulnerability being exploited in the wild (OpenSSL Advisory).

Mitigation and workarounds

Due to the low severity classification, OpenSSL did not issue immediate new releases. However, fixes have been made available in the OpenSSL git repository through the following commits: commit 5b139f95 (for 3.2), commit f3fc5808 (for 3.1), and commit 050d263 (for 3.0). These fixes will be included in future OpenSSL releases (OpenSSL Advisory).

Additional resources


SourceThis report was generated using AI

Related MySQL vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61109MEDIUM6.5
  • MySQL logoMySQL
  • mysql:8.4::mecab.src
NoYesJul 21, 2026
CVE-2026-61108MEDIUM6.5
  • MySQL logoMySQL
  • mysql-devel
NoYesJul 21, 2026
CVE-2026-61144MEDIUM4.9
  • MySQL logoMySQL
  • mysql-common
NoYesJul 21, 2026
CVE-2026-61128MEDIUM4.9
  • MySQL logoMySQL
  • mysql-shell
NoYesJul 21, 2026
CVE-2026-61096LOW2.9
  • MySQL logoMySQL
  • mysql8.4-errmsg
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management