GHSA-299c-jvhc-gxj8 · Severity: medium — Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when...
Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. It may also happen by accident in normal operation. This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL 1.0.2 is also not affected by this issue.
Conclusion & alert: CVE-2024-2511 is rated Moderate Risk (63.2/100): CVSS Medium severity, with high exploitation likelihood (EPSS 54.03%, 99th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +45.19% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 8.83% | 54.03% | +45.19% |
| 2 | 2026-06-02 | 9.05% | 8.83% | -0.22% |
| 3 | 2026-05-22 | — | 9.05% | — |
Full EPSS history (72 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.9 | 3.1 | MEDIUM |
|
2.2 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-299c-jvhc-gxj8 · Severity: medium — Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when...
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2024-2511: 1 source package rows (openssl); 162 state rows across 7 repos (3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 10, open 152. | https://security.alpinelinux.org/vuln/CVE-2024-2511 |
debian
|
not yet assigned | CVE-2024-2511 not yet assigned priority: Debian including 1 source packages (openssl), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2024-2511 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2024-2511 |
suse
|
medium | CVE-2024-2511 severity moderate: SUSE including 496 source package names (1.21-13.11:libopenssl1_1-1.1.1l-150500.17.28.2, 1.21-13.11:libopenssl1_1-hmac-1.1.1l-150500.17.28.2, …), 1264 product×package rows across 290 product lines (Container bci/bci-base-fips, Container bci/bci-init, … (290 product lines)): Fixed 818, Known Not Affected 246, Known Affected 200. | https://www.suse.com/security/cve/CVE-2024-2511/ |
ubuntu
|
low | CVE-2024-2511 low priority: Ubuntu including 5 source packages (edk2, nodejs, openssl, openssl-fips, openssl1.0), 49 status rows across 11 suites (bionic, focal, jammy, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): needs-triage 13, DNE 12, not-affected 10, released 9, ignored 3, needed 2. | https://ubuntu.com/security/CVE-2024-2511 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||