{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/rhel7els/vex/2024/cve-2024-4603-els_os-rhel7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-06-13T03:10:19Z",
      "generator": {
        "date": "2026-06-13T03:10:19Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2024-4603-ELS_OS-RHEL7ELS",
      "initial_release_date": "2024-05-16T00:00:00Z",
      "revision_history": [
        {
          "date": "2024-05-16T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-13T03:10:19Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2024-4603"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 7",
                "product": {
                  "name": "Red Hat Enterprise Linux 7",
                  "product_id": "Red-Hat-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:redhat:enterprise_linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl11-static-1:1.1.1k-7.el7.x86_64",
                "product": {
                  "name": "openssl11-static-1:1.1.1k-7.el7.x86_64",
                  "product_id": "openssl11-static-1:1.1.1k-7.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl11-static@1.1.1k-7.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl11-devel-1:1.1.1k-7.el7.x86_64",
                "product": {
                  "name": "openssl11-devel-1:1.1.1k-7.el7.x86_64",
                  "product_id": "openssl11-devel-1:1.1.1k-7.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl11-devel@1.1.1k-7.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl11-libs-1:1.1.1k-7.el7.x86_64",
                "product": {
                  "name": "openssl11-libs-1:1.1.1k-7.el7.x86_64",
                  "product_id": "openssl11-libs-1:1.1.1k-7.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl11-libs@1.1.1k-7.el7?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl11-1:1.1.1k-7.el7.x86_64",
                "product": {
                  "name": "openssl11-1:1.1.1k-7.el7.x86_64",
                  "product_id": "openssl11-1:1.1.1k-7.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl11@1.1.1k-7.el7?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl11-static-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "openssl11-static-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
                  "product_id": "openssl11-static-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl11-static@1.1.1k-7.el7.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl11-devel-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "openssl11-devel-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
                  "product_id": "openssl11-devel-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl11-devel@1.1.1k-7.el7.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl11-libs-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "openssl11-libs-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
                  "product_id": "openssl11-libs-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl11-libs@1.1.1k-7.el7.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl11-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "openssl11-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
                  "product_id": "openssl11-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/openssl11@1.1.1k-7.el7.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl11-static-1:1.1.1k-7.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl11-static-1:1.1.1k-7.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "openssl11-static-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl11-static-1:1.1.1k-7.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl11-static-1:1.1.1k-7.el7.x86_64"
        },
        "product_reference": "openssl11-static-1:1.1.1k-7.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl11-devel-1:1.1.1k-7.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl11-devel-1:1.1.1k-7.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "openssl11-devel-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl11-devel-1:1.1.1k-7.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl11-devel-1:1.1.1k-7.el7.x86_64"
        },
        "product_reference": "openssl11-devel-1:1.1.1k-7.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl11-libs-1:1.1.1k-7.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl11-libs-1:1.1.1k-7.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "openssl11-libs-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl11-libs-1:1.1.1k-7.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl11-libs-1:1.1.1k-7.el7.x86_64"
        },
        "product_reference": "openssl11-libs-1:1.1.1k-7.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl11-1:1.1.1k-7.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl11-1:1.1.1k-7.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "openssl11-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl11-1:1.1.1k-7.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:openssl11-1:1.1.1k-7.el7.x86_64"
        },
        "product_reference": "openssl11-1:1.1.1k-7.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2024-4603",
      "notes": [
        {
          "category": "description",
          "text": "Issue summary: Checking excessively long DSA keys or parameters may be very\nslow.\nImpact summary: Applications that use the functions EVP_PKEY_param_check()\nor EVP_PKEY_public_check() to check a DSA public key or DSA parameters may\nexperience long delays. Where the key or parameters that are being checked\nhave been obtained from an untrusted source this may lead to a Denial of\nService.\nThe functions EVP_PKEY_param_check() or EVP_PKEY_public_check() perform\nvarious checks on DSA parameters. Some of those computations take a long time\nif the modulus (`p` parameter) is too large.\nTrying to use a very large modulus is slow and OpenSSL will not allow using\npublic keys with a modulus which is over 10,000 bits in length for signature\nverification. However the key and parameter check functions do not limit\nthe modulus size when performing the checks.\nAn application that calls EVP_PKEY_param_check() or EVP_PKEY_public_check()\nand supplies a key or parameters obtained from an untrusted source could be\nvulnerable to a Denial of Service attack.\nThese functions are not called by OpenSSL itself on untrusted DSA keys so\nonly applications that directly call these functions may be vulnerable.\nAlso vulnerable are the OpenSSL pkey and pkeyparam command line applications\nwhen using the `-check` option.\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\nThe OpenSSL 3.0 and 3.1 FIPS providers are affected by this issue.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Red-Hat-7:openssl11-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:openssl11-1:1.1.1k-7.el7.x86_64",
          "Red-Hat-7:openssl11-devel-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:openssl11-devel-1:1.1.1k-7.el7.x86_64",
          "Red-Hat-7:openssl11-libs-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:openssl11-libs-1:1.1.1k-7.el7.x86_64",
          "Red-Hat-7:openssl11-static-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:openssl11-static-1:1.1.1k-7.el7.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-4603"
        }
      ],
      "release_date": "2024-05-16T00:00:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-06-12T12:57:38.474783Z",
          "details": "Low practical exposure: exploitation requires an attacker to feed excessively large DSA parameters or keys to the specific OpenSSL validation routines (EVP_PKEY_param_check or EVP_PKEY_public_check), which OpenSSL itself does not invoke on untrusted input; the SSL/TLS stack is explicitly unaffected. Remote impact exists only if an application is intentionally designed to accept arbitrary DSA material and route it into these checks (the pkey/pkeyparam “-check” utilities are local-only), so common network entry points do not trigger the vulnerable path. Because the effect is limited to CPU-time denial of service with no confidentiality or integrity impact, this can be safely deprioritized in centrally managed enterprise VM/server environments.",
          "product_ids": [
            "Red-Hat-7:openssl11-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:openssl11-1:1.1.1k-7.el7.x86_64",
            "Red-Hat-7:openssl11-devel-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:openssl11-devel-1:1.1.1k-7.el7.x86_64",
            "Red-Hat-7:openssl11-libs-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:openssl11-libs-1:1.1.1k-7.el7.x86_64",
            "Red-Hat-7:openssl11-static-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:openssl11-static-1:1.1.1k-7.el7.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "Red-Hat-7:openssl11-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:openssl11-1:1.1.1k-7.el7.x86_64",
            "Red-Hat-7:openssl11-devel-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:openssl11-devel-1:1.1.1k-7.el7.x86_64",
            "Red-Hat-7:openssl11-libs-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:openssl11-libs-1:1.1.1k-7.el7.x86_64",
            "Red-Hat-7:openssl11-static-1:1.1.1k-7.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:openssl11-static-1:1.1.1k-7.el7.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}