CVE-2018-0732: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 48.8% chance of exploitation in the next 30 days.

During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o).

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only
  • Node.js Node.js: from 6.0.0, before 6.8.1 (fixed in 6.8.1); from 6.9.0, before 6.14.4 (fixed in 6.14.4); from 8.0.0, before 8.8.1 (fixed in 8.8.1); from 8.9.0, before 8.11.4 (fixed in 8.11.4); from 10.0.0, before 10.9.0 (fixed in 10.9.0)
  • OpenSSL OpenSSL: from 1.0.2, up to and including 1.0.2o; from 1.1.0, up to and including 1.1.0h

Published 2018-06-12. Last modified 2026-10-08.