CVE-2019-1559: Canonical Ubuntu Linux

Medium severity, CVSS 5.9. EPSS: 17.1% chance of exploitation in the next 30 days.

If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • F5 BIG-IP Access Policy Manager: from 12.1.0, up to and including 12.1.5; from 13.0.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.1.0
  • F5 BIG-IP Advanced Firewall Manager: from 12.1.0, up to and including 12.1.5; from 13.0.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.1.0
  • F5 BIG-IP Analytics: from 12.1.0, up to and including 12.1.5; from 13.0.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.1.0
  • F5 BIG-IP Application Acceleration Manager: from 12.1.0, up to and including 12.1.5; from 13.0.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.1.0
  • F5 BIG-IP Application Security Manager: from 12.1.0, up to and including 12.1.5; from 13.0.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.1.0
  • F5 BIG-IP Domain Name System: from 12.1.0, up to and including 12.1.5; from 13.0.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.1.0
  • F5 BIG-IP Edge Gateway: from 12.1.0, up to and including 12.1.5; from 13.0.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.1.0
  • F5 BIG-IP Fraud Protection Service: from 12.1.0, up to and including 12.1.5; from 13.0.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.1.0
  • F5 BIG-IP Global Traffic Manager: from 12.1.0, up to and including 12.1.5; from 13.0.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.1.0
  • F5 BIG-IP Link Controller: from 12.1.0, up to and including 12.1.5; from 13.0.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.1.0
  • F5 BIG-IP Local Traffic Manager: from 12.1.0, up to and including 12.1.5; from 13.0.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.1.0
  • F5 BIG-IP Policy Enforcement Manager: from 12.1.0, up to and including 12.1.5; from 13.0.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.1.0
  • F5 BIG-IP Webaccelerator: from 12.1.0, up to and including 12.1.5; from 13.0.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.1.0
  • F5 BIG-IQ Centralized Management: from 6.0.0, up to and including 6.1.0; from 7.0.0, up to and including 7.1.0
  • F5 Traffix Signaling Delivery Controller: from 5.0.0, up to and including 5.1.0; version 4.4.0 only
  • Fedoraproject Fedora: version 29 only; version 30 only; version 31 only
  • McAfee Agent: from 5.6.0, up to and including 5.6.4
  • McAfee Data Exchange Layer: from 4.0.0, before 6.0.0 (fixed in 6.0.0)
  • McAfee Threat Intelligence Exchange Server: from 2.0.0, before 3.0.0 (fixed in 3.0.0)
  • McAfee Web Gateway: from 7.0.0, before 9.0.0 (fixed in 9.0.0)
  • Netapp a220 Firmware: affected versions not specified
  • Netapp a320 Firmware: affected versions not specified
  • Netapp a800 Firmware: affected versions not specified
  • and 57 more

Published 2019-02-27. Last modified 2026-06-17.