Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-rp9h-rf7g-hwgr
No affected components available
Impact
s2n-tls uses the Linux atexit function to register functions that clean up the global state when the process exits. In multi-threaded environments, the atexit handler may clean up state which is still in use by other threads. When this occurs, the exiting process may experience a segmentation fault or other undefined behavior.
Customers of AWS services do not need to take action. Applications using s2n-tls should upgrade to the most recent release of s2n-tls.
Impacted versions: < v1.5.9.
Patches
The patch commit 493b771 is included in s2n-tls v1.5.9 [1]
Workarounds
The atexit handler may be disabled by calling s2n_disable_atexit() prior to initializing s2n-tls. The atexit handler is off by default in the patched versions. For further details, refer to s2n-tls Usage Guide: Initialization and Teardown.
If you have any questions or comments about this advisory, we ask that you contact AWS/Amazon Security via our vulnerability reporting page [2] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue.
[1] https://github.com/aws/s2n-tls/releases/tag/v1.5.9 [2] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting
Measures severity based on intrinsic characteristics of the vulnerability, independent of environment.
No exploitation activity has been observed at this time. Continue routine monitoring.
Probability that this vulnerability will be exploited in the wild within the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard