---
title: "CVE-2022-0778\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2022-0778?format=md
keywords: index, follow
---

# CVE-2022-0778

Publication date 15 March 2022

Last updated 26 November 2025

---

Ubuntu priority

**High**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2022-0778?format=md#impact-score)

Toggle side navigation

## Description

The BN\_mod\_sqrt() function, which computes a modular square root, contains
a bug that can cause it to loop forever for non-prime moduli. Internally
this function is used when parsing certificates that contain elliptic curve
public keys in compressed form or explicit elliptic curve parameters with a
base point encoded in compressed form. It is possible to trigger the
infinite loop by crafting a certificate that has invalid explicit curve
parameters. Since certificate parsing happens prior to verification of the
certificate signature, any process that parses an externally supplied
certificate may thus be subject to a denial of service attack. The infinite
loop can also be reached when parsing crafted private keys as they can
contain explicit elliptic curve parameters. Thus vulnerable situations
include: - TLS clients consuming server certificates - TLS servers
consuming client certificates - Hosting providers taking certificates or
private keys from customers - Certificate authorities parsing certification
requests from subscribers - Anything else which parses ASN.1 elliptic curve
parameters Also any other applications that use the BN\_mod\_sqrt() where the
attacker can control the parameter values are vulnerable to this DoS issue.
In the OpenSSL 1.0.2 version the public key is not parsed during initial
parsing of the certificate which makes it slightly harder to trigger the
infinite loop. However any operation which requires the public key from the
certificate will trigger the infinite loop. In particular the attacker can
use a self-signed certificate to trigger the loop during verification of
the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1
and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th
March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL
1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected
1.0.2-1.0.2zc).

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| edk2 | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Fixed 2022.02-3ubuntu0.22.04.4 |
| 21.10 impish | Ignored end of life |
| 20.04 LTS focal | Vulnerable |
| 18.04 LTS bionic | Vulnerable |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| nodejs | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Fixed 12.22.9~dfsg-1ubuntu3.1 |
| 21.10 impish | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| openssl | 26.04 LTS resolute | Fixed 3.0.2-0ubuntu1 |
| 25.10 questing | Fixed 3.0.2-0ubuntu1 |
| 25.04 plucky | Fixed 3.0.2-0ubuntu1 |
| 24.10 oracular | Fixed 3.0.2-0ubuntu1 |
| 24.04 LTS noble | Fixed 3.0.2-0ubuntu1 |
| 23.10 mantic | Fixed 3.0.2-0ubuntu1 |
| 23.04 lunar | Fixed 3.0.2-0ubuntu1 |
| 22.10 kinetic | Fixed 3.0.2-0ubuntu1 |
| 22.04 LTS jammy | Fixed 3.0.2-0ubuntu1 |
| 21.10 impish | Fixed 1.1.1l-1ubuntu1.2 |
| 20.04 LTS focal | Fixed 1.1.1f-1ubuntu2.12 |
| 18.04 LTS bionic | Fixed 1.1.1-1ubuntu2.1~18.04.15 |
| 16.04 LTS xenial | Fixed 1.0.2g-1ubuntu4.20+esm2  Ubuntu Pro |
| 14.04 LTS trusty | Fixed 1.0.1f-1ubuntu2.27+esm5  Ubuntu Pro |
| openssl1.0 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 25.04 plucky | Not in release |
| 24.10 oracular | Not in release |
| 24.04 LTS noble | Not in release |
| 23.10 mantic | Not in release |
| 23.04 lunar | Not in release |
| 22.10 kinetic | Not in release |
| 22.04 LTS jammy | Not in release |
| 21.10 impish | Not in release |
| 20.04 LTS focal | Not in release |
| 18.04 LTS bionic | Fixed 1.0.2n-1ubuntu5.8 |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0778)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-0778)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2022-0778)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2022-0778)

### Related Ubuntu Security Notices (USN)

+ [USN-5328-1](https://usn.ubuntu.com/USN-5328-1)
+ OpenSSL vulnerability
+ 15 March 2022

+ [USN-5328-2](https://usn.ubuntu.com/USN-5328-2)
+ OpenSSL vulnerability
+ 15 March 2022

+ [USN-6457-1](https://usn.ubuntu.com/USN-6457-1)
+ Node.js vulnerabilities
+ 30 October 2023

+ [USN-7894-1](https://usn.ubuntu.com/USN-7894-1)
+ EDK II vulnerabilities
+ 26 November 2025

### Other references

* <https://www.openssl.org/news/secadv/20220315.txt>
* <https://www.cve.org/CVERecord?id=CVE-2022-0778>
