---
title: "CVE-2022-2097\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2022-2097?format=md
keywords: index, follow
---

# CVE-2022-2097

Publication date 5 July 2022

Last updated 18 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.3 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2022-2097?format=md#impact-score)

Toggle side navigation

## Description

AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised
implementation will not encrypt the entirety of the data under some
circumstances. This could reveal sixteen bytes of data that was preexisting
in the memory that wasn't written. In the special case of "in place"
encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL
does not support OCB based cipher suites for TLS and DTLS, they are both
unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL
1.1.1q (Affected 1.1.1-1.1.1p).

[Read the notes from the security team](https://ubuntu.com/security/CVE-2022-2097?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| edk2 | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Not in release |
| nodejs | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Fixed 12.22.9~dfsg-1ubuntu3.1 |
| 21.10 impish | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| openssl | 26.04 LTS resolute | Fixed 3.0.5-2ubuntu1 |
| 25.10 questing | Fixed 3.0.5-2ubuntu1 |
| 25.04 plucky | Fixed 3.0.5-2ubuntu1 |
| 24.10 oracular | Fixed 3.0.5-2ubuntu1 |
| 24.04 LTS noble | Fixed 3.0.5-2ubuntu1 |
| 23.10 mantic | Fixed 3.0.5-2ubuntu1 |
| 23.04 lunar | Fixed 3.0.5-2ubuntu1 |
| 22.10 kinetic | Fixed 3.0.5-2ubuntu1 |
| 22.04 LTS jammy | Fixed 3.0.2-0ubuntu1.6 |
| 21.10 impish | Fixed 1.1.1l-1ubuntu1.6 |
| 20.04 LTS focal | Fixed 1.1.1f-1ubuntu2.16 |
| 18.04 LTS bionic | Fixed 1.1.1-1ubuntu2.1~18.04.20 |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| openssl1.0 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 25.04 plucky | Not in release |
| 24.10 oracular | Not in release |
| 24.04 LTS noble | Not in release |
| 23.10 mantic | Not in release |
| 23.04 lunar | Not in release |
| 22.10 kinetic | Not in release |
| 22.04 LTS jammy | Not in release |
| 21.10 impish | Not in release |
| 20.04 LTS focal | Not in release |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

affected file isn't used in edk2

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.3 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2097)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-2097)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2022-2097)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2022-2097)

### Related Ubuntu Security Notices (USN)

+ [USN-5502-1](https://usn.ubuntu.com/USN-5502-1)
+ OpenSSL vulnerability
+ 5 July 2022

+ [USN-6457-1](https://usn.ubuntu.com/USN-6457-1)
+ Node.js vulnerabilities
+ 30 October 2023

### Other references

* <https://www.openssl.org/news/secadv/20220705.txt>
* <https://www.cve.org/CVERecord?id=CVE-2022-2097>
