CVE-2016-8610: Debian Linux

High severity, CVSS 7.5. EPSS: 39.7% chance of exploitation in the next 30 days.

A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Fujitsu m10-1 Firmware: before xcp2361 (fixed in xcp2361); from xcp3000, before xcp3070 (fixed in xcp3070)
  • Fujitsu m10-4 Firmware: before xcp2361 (fixed in xcp2361); from xcp3000, before xcp3070 (fixed in xcp3070)
  • Fujitsu m10-4s Firmware: before xcp2361 (fixed in xcp2361); from xcp3000, before xcp3070 (fixed in xcp3070)
  • Fujitsu m12-1 Firmware: before xcp2361 (fixed in xcp2361); from xcp3000, before xcp3070 (fixed in xcp3070)
  • Fujitsu m12-2 Firmware: before xcp2361 (fixed in xcp2361); from xcp3000, before xcp3070 (fixed in xcp3070)
  • Fujitsu m12-2s Firmware: before xcp2361 (fixed in xcp2361); from xcp3000, before xcp3070 (fixed in xcp3070)
  • Netapp Clustered Data Ontap: affected versions not specified
  • Netapp Clustered Data Ontap Antivirus Connector: affected versions not specified
  • Netapp CN1610 Firmware: affected versions not specified
  • Netapp Data Ontap: affected versions not specified
  • Netapp Data Ontap Edge: affected versions not specified
  • Netapp E-Series Santricity OS Controller: from 11.0, up to and including 11.40
  • Netapp Host Agent: affected versions not specified
  • Netapp Oncommand Balance: affected versions not specified
  • Netapp Oncommand Unified Manager: affected versions not specified
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Ontap Select Deploy: affected versions not specified
  • Netapp Service Processor: affected versions not specified
  • Netapp Smi-S Provider: affected versions not specified
  • Netapp Snapcenter Server: affected versions not specified
  • Netapp Snapdrive: affected versions not specified
  • Netapp Storagegrid: affected versions not specified
  • Netapp Storagegrid Webscale: affected versions not specified
  • OpenSSL OpenSSL: from 1.0.2, up to and including 1.0.2h; version 0.9.8 only; version 1.0.1 only; version 1.1.0 only
  • and 20 more

Published 2017-11-13. Last modified 2026-06-17.