CVE-2022-29242

Source
https://cve.org/CVERecord?id=CVE-2022-29242
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-29242.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-29242
Aliases
  • GHSA-2rmw-8wpg-vgw5
Downstream
Published
2022-05-24T14:55:13Z
Modified
2026-07-15T00:27:41.768059Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Buffer Overflow on creating key transport blob in GOST Engine
Details

GOST engine is a reference implementation of the Russian GOST crypto algorithms for OpenSSL. TLS clients using GOST engine when ciphersuite TLS_GOSTR341112_256_WITH_KUZNYECHIK_CTR_OMAC is agreed and the server uses 512 bit GOST secret keys are vulnerable to buffer overflow. GOST engine version 3.0.1 contains a patch for this issue. Disabling ciphersuite TLS_GOSTR341112_256_WITH_KUZNYECHIK_CTR_OMAC is a possible workaround.

Database specific
{
    "cwe_ids": [
        "CWE-120"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29242.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/gost-engine/engine

Affected ranges

Type
GIT
Repo
https://github.com/gost-engine/engine
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.0.1"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:gost_engine_project:gost_engine:*:*:*:*:*:*:*:*"
}

Affected versions

v3.*
v3.0.0

Database specific

vanir_signatures_modified
"2026-07-15T00:27:41Z"
vanir_signatures
[
    {
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "e_gost_err.c"
        },
        "signature_type": "Line",
        "source": "https://github.com/gost-engine/engine/commit/c6655a0b620a3e31f085cc906f8073fe81b2fad3",
        "digest": {
            "line_hashes": [
                "181079042129152464932669655050909846368",
                "158295315304811067947470668990101074335",
                "239758865765949342379508158066880226757",
                "7856286627472673225455720181777985340"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2022-29242-518bdba1"
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "gost_ec_keyx.c"
        },
        "signature_type": "Line",
        "source": "https://github.com/gost-engine/engine/commit/c6655a0b620a3e31f085cc906f8073fe81b2fad3",
        "digest": {
            "line_hashes": [
                "65030514501109260630237999873123317328",
                "118759800526282905302103490401707480352",
                "25217270377180783317180417274478535203",
                "82835145014064360693273568063469535198",
                "190573629692466551360361712816298746329",
                "270785022693191878437097098274107173792",
                "59505043026629093783673545315870750222",
                "66807662697499471765169844625495725539",
                "259928869894521617717612055134712520778"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2022-29242-7c5971bf"
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "e_gost_err.h"
        },
        "signature_type": "Line",
        "source": "https://github.com/gost-engine/engine/commit/c6655a0b620a3e31f085cc906f8073fe81b2fad3",
        "digest": {
            "line_hashes": [
                "225974880740951108040578185193683290431",
                "83795847996781818239151978839630099984",
                "92443563628866274598904886782383012572",
                "271866978301397155848059525930755811876"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2022-29242-8a1db8d3"
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "gost_ec_keyx.c"
        },
        "signature_type": "Line",
        "source": "https://github.com/gost-engine/engine/commit/7df766124f87768b43b9e8947c5a01e17545772c",
        "digest": {
            "line_hashes": [
                "262602055950945910048374951381244017043",
                "133575904534108703594450698815216688908",
                "306646113463739568394603861208556252657",
                "159722934626170867728314086069424947872",
                "204330586165551716996370019380505897401",
                "79117507171449429347525376120382705688",
                "127995012079193092992430084288135743223",
                "204872776069466686650936831459702920582",
                "67801462794236172636082648689476191052"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2022-29242-931738df"
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "gost_ec_keyx.c",
            "function": "pkey_gost2018_encrypt"
        },
        "signature_type": "Function",
        "source": "https://github.com/gost-engine/engine/commit/c6655a0b620a3e31f085cc906f8073fe81b2fad3",
        "digest": {
            "length": 2773.0,
            "function_hash": "88359506090462606094284207342429409843"
        },
        "id": "CVE-2022-29242-fc24cf99"
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "gost_ec_keyx.c",
            "function": "pkey_GOST_ECcp_encrypt"
        },
        "signature_type": "Function",
        "source": "https://github.com/gost-engine/engine/commit/7df766124f87768b43b9e8947c5a01e17545772c",
        "digest": {
            "length": 2743.0,
            "function_hash": "139848417904887730486267643683863266030"
        },
        "id": "CVE-2022-29242-fe72abfd"
    }
]
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-29242.json"