CVE-2024-2511 | Unbounded memory growth with session handling in TLSv1.3

Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. It may also happen by accident in normal operation. This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL 1.0.2 is also not affected by this issue.

Published: 2024-04-08 Last update: 2026-05-12 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2024-2511 is rated Moderate Risk (63.2/100): CVSS Medium severity, with high exploitation likelihood (EPSS 54.03%, 99th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +45.19% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2024-2511

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 8.83% 54.03% +45.19%
2 2026-06-02 9.05% 8.83% -0.22%
3 2026-05-22 9.05%

Full EPSS history (72 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2024-2511

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.9 3.1 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
2.2 3.6 134c704f-9b21-4f2e-91b3-4a467353bcc0

Weakness enumeration for CVE-2024-2511

GitHub Security Advisory for CVE-2024-2511

GHSA-299c-jvhc-gxj8 · Severity: medium — Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when...

OS Trackers for CVE-2024-2511

vendor priority summary link
alpine CVE-2024-2511: 1 source package rows (openssl); 162 state rows across 7 repos (3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 10, open 152. https://security.alpinelinux.org/vuln/CVE-2024-2511
debian not yet assigned CVE-2024-2511 not yet assigned priority: Debian including 1 source packages (openssl), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2024-2511
redhat low https://access.redhat.com/security/cve/CVE-2024-2511
suse medium CVE-2024-2511 severity moderate: SUSE including 496 source package names (1.21-13.11:libopenssl1_1-1.1.1l-150500.17.28.2, 1.21-13.11:libopenssl1_1-hmac-1.1.1l-150500.17.28.2, …), 1264 product×package rows across 290 product lines (Container bci/bci-base-fips, Container bci/bci-init, … (290 product lines)): Fixed 818, Known Not Affected 246, Known Affected 200. https://www.suse.com/security/cve/CVE-2024-2511/
ubuntu low CVE-2024-2511 low priority: Ubuntu including 5 source packages (edk2, nodejs, openssl, openssl-fips, openssl1.0), 49 status rows across 11 suites (bionic, focal, jammy, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): needs-triage 13, DNE 12, not-affected 10, released 9, ignored 3, needed 2. https://ubuntu.com/security/CVE-2024-2511

Affected software / configurations for CVE-2024-2511

Vendor Product Version Raw CPE
No affected products in dataset.

References for CVE-2024-2511

URL Tags
https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce
https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d
https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08
https://github.openssl.org/openssl/extended-releases/commit/5f8d25770ae6437db119dfc951e207271a326640
https://www.openssl.org/news/secadv/20240408.txt
http://www.openwall.com/lists/oss-security/2024/04/08/5
https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html
https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html
https://security.netapp.com/advisory/ntap-20240503-0013/
https://cert-portal.siemens.com/productcert/html/ssa-265688.html
https://cert-portal.siemens.com/productcert/html/ssa-354112.html
https://cert-portal.siemens.com/productcert/html/ssa-398330.html
https://cert-portal.siemens.com/productcert/html/ssa-613116.html
https://cert-portal.siemens.com/productcert/html/ssa-769027.html
https://cert-portal.siemens.com/productcert/html/ssa-915275.html
cvelogic Threat Intelligence