CVE-2016-6302: OpenSSL
High severity, CVSS 7.5. EPSS: 27.8% chance of exploitation in the next 30 days.
The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket length, which allows remote attackers to cause a denial of service via a ticket that is too short.
Affected products
- OpenSSL OpenSSL: version 1.0.1 only; version 1.0.1a only; version 1.0.1b only; version 1.0.1c only; version 1.0.1d only; version 1.0.1e only; …
- Oracle Linux: version 6 only; version 7 only
- Oracle Solaris: version 10 only; version 11.3 only
Published 2016-09-16. Last modified 2026-06-17.