{"schema_version":"1.9.0","id":"CVE-2024-2511","published":"2024-04-08T13:51:12.349Z","modified":"2026-08-12T14:52:03.015941Z","related":["ALSA-2024:9333","CGA-6j5g-x524-ppqj","SUSE-SU-2024:1633-1","SUSE-SU-2024:1634-1","SUSE-SU-2024:1808-1","SUSE-SU-2024:1947-1","SUSE-SU-2024:1949-1","SUSE-SU-2024:2953-1","SUSE-SU-2025:20014-1","openSUSE-SU-2024:13937-1","openSUSE-SU-2024:13942-1"],"summary":"Unbounded memory growth with session handling in TLSv1.3","details":"Issue summary: Some non-default TLS server configurations can cause unbounded\nmemory growth when processing TLSv1.3 sessions\n\nImpact summary: An attacker may exploit certain server configurations to trigger\nunbounded memory growth that would lead to a Denial of Service\n\nThis problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is\nbeing used (but not if early_data support is also configured and the default\nanti-replay protection is in use). In this case, under certain conditions, the\nsession cache can get into an incorrect state and it will fail to flush properly\nas it fills. The session cache will continue to grow in an unbounded manner. A\nmalicious client could deliberately create the scenario for this failure to\nforce a Denial of Service. It may also happen by accident in normal operation.\n\nThis issue only affects TLS servers supporting TLSv1.3. It does not affect TLS\nclients.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL\n1.0.2 is also not affected by this issue.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssl/openssl","events":[{"introduced":"cf2877791ce7508684109664f467c9e40987692f"},{"introduced":"a92271e03a8d0dee507b6f1e7f49512568b2c7ad"},{"introduced":"89cd17a031e022211684eb7eb41190cf1910f9fa"},{"introduced":"e04bd3433fd84e1861bf258ea37928d9845e6a86"},{"fixed":"cd1e967483577ec4a42ebe75942894c10655e2b6"},{"fixed":"8ffa005476942fc89d247448f95077c104efadf1"},{"fixed":"9cff14fd97814baf8a9a07d8447960a64d616ada"},{"fixed":"e04bd3433fd84e1861bf258ea37928d9845e6a86"},{"fixed":"7e4d731b1c07201ad9374c1cd9ac5263bdf35bce"},{"fixed":"b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d"},{"fixed":"e9d7083e241670332e0443da0f0d4ffb52829f08"}],"database_specific":{"extracted_events":[{"introduced":"3.2.0"},{"fixed":"3.2.2"},{"introduced":"3.1.0"},{"fixed":"3.1.6"},{"introduced":"3.0.0"},{"fixed":"3.0.14"},{"introduced":"1.1.1"},{"fixed":"1.1.1y"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["openssl-3.0.13","openssl-3.1.5","openssl-3.2.1","openssl-3.2.0","openssl-3.0.12","openssl-3.1.4","openssl-3.0.11","openssl-3.1.3","openssl-3.0.10","openssl-3.1.2","openssl-3.0.9","openssl-3.1.1","openssl-3.1.0","openssl-3.0.8","openssl-3.0.7","openssl-3.0.6","openssl-3.0.5","openssl-3.0.4","openssl-3.0.3","openssl-3.0.2","openssl-3.0.1","openssl-3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-2511.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["237068005254384937667547875889483844978","113915117782040053630255145392358530759","66103385765130290457162085093933223558","162382651939373866582061212683682848533","76408188136838676687937324189907664685","260125722951887923555973287923469516789","162168863295799619329617944683703962609","159264430167139000382594925269229087884","218625742145348075137939568597510799794","132262577977491748484833362742782862377","149880655905331652701777215391255866459"],"threshold":0.9},"id":"CVE-2024-2511-05d21ef6","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08","target":{"file":"ssl/ssl_sess.c"}},{"deprecated":false,"digest":{"function_hash":"282121092333121823000089348211305663540","length":1940},"id":"CVE-2024-2511-085be921","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d","target":{"file":"ssl/statem/statem_srvr.c","function":"tls_construct_server_hello"}},{"deprecated":false,"digest":{"function_hash":"212954300303107326089724544104956651196","length":2851},"id":"CVE-2024-2511-1ac95f2f","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08","target":{"file":"ssl/ssl_sess.c","function":"ssl_session_dup"}},{"deprecated":false,"digest":{"function_hash":"7635606872942867414870440948978544895","length":2619},"id":"CVE-2024-2511-27ee7cf8","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d","target":{"file":"ssl/ssl_sess.c","function":"ssl_session_dup"}},{"deprecated":false,"digest":{"function_hash":"242839529669032139629079760961191258975","length":1325},"id":"CVE-2024-2511-30888480","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d","target":{"file":"ssl/ssl_lib.c","function":"ssl_update_cache"}},{"deprecated":false,"digest":{"function_hash":"7635606872942867414870440948978544895","length":2619},"id":"CVE-2024-2511-4880e2a0","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce","target":{"file":"ssl/ssl_sess.c","function":"ssl_session_dup"}},{"deprecated":false,"digest":{"line_hashes":["70837027254147380184232394837312893826","35849081333738844367146501708823095500","200567339918318236680609037933296929430","45616768372581396962167201247601357857"],"threshold":0.9},"id":"CVE-2024-2511-4edd43bb","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce","target":{"file":"ssl/ssl_lib.c"}},{"deprecated":false,"digest":{"line_hashes":["175923431394192972363936778328285162033","38339879515594619117610231575660264724","174681001384431283175637828303769415213","131831670793621309890501412306824758312","329438803076000449442289115165415388072","195726165541695366769363416913210763411"],"threshold":0.9},"id":"CVE-2024-2511-535073f1","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d","target":{"file":"ssl/statem/statem_srvr.c"}},{"deprecated":false,"digest":{"line_hashes":["70837027254147380184232394837312893826","35849081333738844367146501708823095500","200567339918318236680609037933296929430","45616768372581396962167201247601357857"],"threshold":0.9},"id":"CVE-2024-2511-617b54c9","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d","target":{"file":"ssl/ssl_lib.c"}},{"deprecated":false,"digest":{"function_hash":"242839529669032139629079760961191258975","length":1325},"id":"CVE-2024-2511-6cc0b590","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce","target":{"file":"ssl/ssl_lib.c","function":"ssl_update_cache"}},{"deprecated":false,"digest":{"function_hash":"282121092333121823000089348211305663540","length":1940},"id":"CVE-2024-2511-8815d9ec","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce","target":{"file":"ssl/statem/statem_srvr.c","function":"tls_construct_server_hello"}},{"deprecated":false,"digest":{"line_hashes":["237068005254384937667547875889483844978","113915117782040053630255145392358530759","66103385765130290457162085093933223558","162382651939373866582061212683682848533","76408188136838676687937324189907664685","260125722951887923555973287923469516789","162168863295799619329617944683703962609","159264430167139000382594925269229087884","218625742145348075137939568597510799794","132262577977491748484833362742782862377","149880655905331652701777215391255866459"],"threshold":0.9},"id":"CVE-2024-2511-8d10cd60","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d","target":{"file":"ssl/ssl_sess.c"}},{"deprecated":false,"digest":{"line_hashes":["237068005254384937667547875889483844978","113915117782040053630255145392358530759","66103385765130290457162085093933223558","162382651939373866582061212683682848533","76408188136838676687937324189907664685","260125722951887923555973287923469516789","162168863295799619329617944683703962609","159264430167139000382594925269229087884","218625742145348075137939568597510799794","132262577977491748484833362742782862377","149880655905331652701777215391255866459"],"threshold":0.9},"id":"CVE-2024-2511-90c67130","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce","target":{"file":"ssl/ssl_sess.c"}},{"deprecated":false,"digest":{"function_hash":"179926413095981420004483889142535469138","length":2052},"id":"CVE-2024-2511-a7e112c0","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08","target":{"file":"ssl/statem/statem_srvr.c","function":"tls_construct_server_hello"}},{"deprecated":false,"digest":{"function_hash":"122597478856692738374150515729258319484","length":1338},"id":"CVE-2024-2511-adc20d36","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08","target":{"file":"ssl/ssl_lib.c","function":"ssl_update_cache"}},{"deprecated":false,"digest":{"line_hashes":["28170854778703993674264004058177114599","73132526844288570625317440636111911761","177405411499435185068645597737938634778","224809958623850711330610094965797758930","295554444428855106393106961197201359586"],"threshold":0.9},"id":"CVE-2024-2511-c377fa22","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e04bd3433fd84e1861bf258ea37928d9845e6a86","target":{"file":"include/openssl/opensslv.h"}},{"deprecated":false,"digest":{"line_hashes":["93537334691950515621301137830879284931","35849081333738844367146501708823095500","200567339918318236680609037933296929430","45616768372581396962167201247601357857"],"threshold":0.9},"id":"CVE-2024-2511-ce686be8","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08","target":{"file":"ssl/ssl_lib.c"}},{"deprecated":false,"digest":{"line_hashes":["175923431394192972363936778328285162033","38339879515594619117610231575660264724","174681001384431283175637828303769415213","131831670793621309890501412306824758312","329438803076000449442289115165415388072","195726165541695366769363416913210763411"],"threshold":0.9},"id":"CVE-2024-2511-debfdb2d","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce","target":{"file":"ssl/statem/statem_srvr.c"}},{"deprecated":false,"digest":{"line_hashes":["307259160925884979239909551177310072787","259789776830101890545412969749917438549","240979021145574152778594971926175841334","307251461390486550372699034100303709344","307443394972201777838578310877614697806","195726165541695366769363416913210763411"],"threshold":0.9},"id":"CVE-2024-2511-f21161fc","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08","target":{"file":"ssl/statem/statem_srvr.c"}}],"vanir_signatures_modified":"2026-08-12T14:52:03Z"}}],"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/04/08/5"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-265688.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-354112.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-398330.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-613116.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-769027.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-915275.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/2xxx/CVE-2024-2511.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-2511"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240503-0013/"},{"type":"ADVISORY","url":"https://www.openssl.org/news/secadv/20240408.txt"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08"},{"type":"FIX","url":"https://github.openssl.org/openssl/extended-releases/commit/5f8d25770ae6437db119dfc951e207271a326640"}],"database_specific":{"cna_assigner":"openssl","cwe_ids":["CWE-1325"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/2xxx/CVE-2024-2511.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}