CyberRota Analysis
AI-GeneratedA vulnerability exists in servers that improperly manage SSLContext references when using the sni_callback function, allowing a remote, unauthenticated TLS client to crash the server or exploit a freed pointer. This critical issue primarily impacts servers that create or replace SSLContext instances per connection without maintaining a reference to the original context. Organizations operating such servers should prioritize immediate remediation to prevent potential service disruptions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected. Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected.