{"id":"CVE-2022-41646","details":"Insufficient control flow management in the Intel(R) IPP Cryptography software before version 2021.6 may allow an unauthenticated user to potentially enable information disclosure via local access.","modified":"2026-04-12T03:22:12.369240Z","published":"2023-05-10T14:15:17.533Z","references":[{"type":"ADVISORY","url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00788.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/intel/ipp-crypto","events":[{"introduced":"0"},{"fixed":"3ae57715fbc7383ef527cab0b824d736b60fa06d"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"2021.6"}]}}],"versions":["ippcp_2019b_r","ippcp_2020u2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41646.json","vanir_signatures_modified":"2026-04-12T03:22:12Z","vanir_signatures":[{"digest":{"threshold":0.9,"line_hashes":["51194992674961492298152473399897543936","132677568609380978192659305190015857248","32646083007536444585729126544387837494","239882765690651000055382967116026579131","189322023557366075126099975441443970422","330268084395751880699234104297565448489","266293417531504996771998711730814118916","8160892867571796696690146917916139164","252528195329660562128195036255791306947","105373181970770377867735725250769825690","147942444979130069642034465459892867685","3978291058030490390783678210286856113","143282075915455432901684268661007218590","152737916516215279382647248917159032020","325472036864298574969808328553040142956","111668114001569559505200753837709320482","232798077785044640732177841902914801603","111187210706172582687346188806984936375","305082314268668844818215131950340470695","84422151201703160549183736974091868192","153781471062708307123536000279773014527"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-0808becf","target":{"file":"sources/ippcp/crypto_mb/include/crypto_mb/cpu_features.h"},"signature_type":"Line"},{"digest":{"function_hash":"72164568002694381910145998708124922207","length":105},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-0869a558","target":{"file":"sources/ippcp/crypto_mb/src/common/cpu_features.c","function":"mbx_get_algo_info"},"signature_type":"Function"},{"digest":{"function_hash":"326319870992245697287363540907547875763","length":4144},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-167f25dd","target":{"file":"sources/ippcp/crypto_mb/src/sm3/sm3_update_mb16.c","function":"mbx_sm3_update_mb16"},"signature_type":"Function"},{"digest":{"threshold":0.9,"line_hashes":["181355626640618997327699939275985386140","211069912694616063768500432969138902827","336876264669617607620906708821711659356","276821994078566233649556701243980399395","185961005823292824560890216579626489802","26849996834456678461220130469924923332","51251920736441391054047769290971781167"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-1fb454c4","target":{"file":"sources/ippcp/crypto_mb/include/internal/sm3/sm3_mb8.h"},"signature_type":"Line"},{"digest":{"threshold":0.9,"line_hashes":["148942927304083568989132637410508112456","239428298914949357280547963220829113859","296095697648078275777065257845804505123","139315337259084269860747520536000657661","104167482604598890957158543957290024119","191955425375436891011991154903176535449","150181746037875653326925249631485182717","103556033073026905763760782119759419068"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-24e2143f","target":{"file":"sources/ippcp/crypto_mb/src/common/ifma_cvt52.c"},"signature_type":"Line"},{"digest":{"threshold":0.9,"line_hashes":["96985207377438089016711833751687309118","214218716576535604021794447835016727872","324462282465298339850208936807287909793","196982250894945102696498187192410963349","164042540964215667957036805699052423071"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-2d067027","target":{"file":"sources/ippcp/crypto_mb/include/crypto_mb/sm3.h"},"signature_type":"Line"},{"digest":{"threshold":0.9,"line_hashes":["122460984803148316076689377800723255077","116465067066453720102278607929932914513","32016363309899383356759039729117392892","286574866747972318570350383451413336548","291974248267969143889848287325036311117","34346997565903029609257242822688212468","319908994806434876254337822634560823479","20886128272004724414613461079834305052","324505201032864688937376323995705292759","88699682576784000192895850422911222413"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-31df101f","target":{"file":"sources/ippcp/crypto_mb/src/sm3/sm3_final_mb8.c"},"signature_type":"Line"},{"digest":{"threshold":0.9,"line_hashes":["172607015968561093239707710824101347908","183341422024062265574785174608548771999","149428269986561524590656282925269051715","162799662803477057989179335850349915042","208099130815580179810883352782570540030"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-334409ec","target":{"file":"sources/ippcp/crypto_mb/src/sm4/sm4_cfb_mb16.c"},"signature_type":"Line"},{"digest":{"function_hash":"296231926010057030040003617315241077496","length":1898},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-35c0b825","target":{"file":"sources/ippcp/crypto_mb/src/sm4/sm4_cbc_mb16.c","function":"sm4_cbc_enc_kernel_mb16"},"signature_type":"Function"},{"digest":{"function_hash":"131395330963121665840460519009599311345","length":7530},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-37e8d258","target":{"file":"sources/ippcp/crypto_mb/src/sm4/sm4_ctr_mb16.c","function":"sm4_ctr128_kernel_mb16"},"signature_type":"Function"},{"digest":{"threshold":0.9,"line_hashes":["336283968436092052661422179764552115751","35924720608438695014260928334293266138","86454851526731442755226630283955069214","253855312008331970998287153515581384196","40955403075531279759998607682648084099"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-395e9ae0","target":{"file":"sources/ippcp/crypto_mb/src/sm4/sm4_ctr_mb16.c"},"signature_type":"Line"},{"digest":{"function_hash":"141786868468865867275998765480271185701","length":2872},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-63507c2c","target":{"file":"sources/ippcp/crypto_mb/src/sm3/sm3_final_mb8.c","function":"sm3_final_mb8"},"signature_type":"Function"},{"digest":{"threshold":0.9,"line_hashes":["323603929162884652388079073847781601073","195077594805188778762773256312146109353","274039838880369779293213182550540273052","27128335655863808723580992159733881743","16352354556388654467021347458833842179","173612946474481228924956337659414276478","260328141500070317449553367013647415910","268449496821510865598986969053913793922","242476794559783889578886360300093938568","134937273247537702248136443277390805555","213296986408644897045925120853550472815","93932823068377284712594309457662823503","9076041695835862517308706930287368151","1201458250835179141597953158609493430","326878575811185317897581465478260711423","105306143840547068013811040840952276641","25544834727008810072652356036860118121","209668240090709464347807679173286488434","60136390747599957211863850236271012330","200549101603244236554228781616151412802"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-641bfb50","target":{"file":"sources/ippcp/crypto_mb/src/sm3/sm3_update_mb16.c"},"signature_type":"Line"},{"digest":{"threshold":0.9,"line_hashes":["3714468907545302226504609208823083758","119988183997366524201678624740521075584","186058977057303279443058653683785273269","330798777556666900290156262930926526352","54748527953593387312041375088915704069"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-66ef9ecf","target":{"file":"sources/ippcp/crypto_mb/src/sm4/sm4_cbc_mb16.c"},"signature_type":"Line"},{"digest":{"function_hash":"269378509519593696320020899285050629013","length":9391},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-6a0bce5f","target":{"file":"sources/ippcp/crypto_mb/src/sm3/sm3_avx512_mb8.c","function":"sm3_avx512_mb8"},"signature_type":"Function"},{"digest":{"function_hash":"19320797201887949552113582229114294653","length":2508},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-71eb534b","target":{"file":"sources/ippcp/crypto_mb/include/internal/sm3/sm3_common.h","function":"TRANSPOSE_8X16_I32"},"signature_type":"Function"},{"digest":{"threshold":0.9,"line_hashes":["323603929162884652388079073847781601073","38077079365827791618101172568985304271","141983211253388317260723475453985937962","202171898247222181185853799694605228472","266812983630083946086988746534644632167","322148859017972339778631737660064516818","184404178563424046982704967796974615952","114427052939930546515013326643939462691","254907254583858096881141553328804377636","267107342800250363325762987088526334678","65188570948837678661037919600733868942","95529631318277283771137619983505879437","163486131439566323459767706438566465821"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-768b6936","target":{"file":"sources/ippcp/crypto_mb/src/sm3/sm3_final_mb16.c"},"signature_type":"Line"},{"digest":{"threshold":0.9,"line_hashes":["168310660636184224597826200223010614969","257659154513835543421296198693300337614","222637611395021825717875987111152350152","96946370936884027990661123248493822241","175442142042864702105330086328380118564","58646886898645171033955840733323346746","258698776855554041395877456337862141227","242384365917444707411546617176711371464","323785609586294925920472425893414198993","160470594639772294983838419385275209470"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-77dd3bfb","target":{"file":"sources/ippcp/crypto_mb/src/common/cpu_features.c"},"signature_type":"Line"},{"digest":{"threshold":0.9,"line_hashes":["255355024300830570232030307095168300000","44915735303979787497680016441167806257","52377391571857690574503982471813256398","27808559885241392431106044527092941102"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-7f5677da","target":{"file":"sources/ippcp/crypto_mb/include/internal/sm3/sm3_mb16.h"},"signature_type":"Line"},{"digest":{"function_hash":"168834833683417059245973731262837531523","length":1818},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-851b2e09","target":{"file":"sources/ippcp/crypto_mb/src/sm4/sm4_ofb_mb16.c","function":"sm4_ofb_kernel_mb16"},"signature_type":"Function"},{"digest":{"function_hash":"90803229492130904788106280106466665709","length":1804},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-8b4d8419","target":{"file":"sources/ippcp/crypto_mb/src/x25519/ifma_x25519.c","function":"(ed25519_sqr_latency_)"},"signature_type":"Function"},{"digest":{"threshold":0.9,"line_hashes":["6798992129891162648002380073878541677","41186216975302595232501437325201569528","121447172885230431495948362720523711671","145223284075023929469016415334512279504","71196297376566466300471919479755732228"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-948f141b","target":{"file":"sources/ippcp/crypto_mb/src/x25519/ifma_x25519.c"},"signature_type":"Line"},{"digest":{"function_hash":"163473591862839561141105512775893348021","length":6027},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-a1911344","target":{"file":"sources/ippcp/crypto_mb/src/sm4/sm4_ecb_mb16.c","function":"sm4_ecb_kernel_mb16"},"signature_type":"Function"},{"digest":{"function_hash":"198584163130250328836007303970125109806","length":2128},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-a9113bb7","target":{"file":"sources/ippcp/crypto_mb/src/sm4/sm4_cfb_mb16.c","function":"sm4_cfb128_enc_kernel_mb16"},"signature_type":"Function"},{"digest":{"threshold":0.9,"line_hashes":["229878166573660987070183931556908294491","16763557871349823495232365752787404879","110518247905097148226458700472338139640","311554527012472979113586433711554665726","81090435586966955559747832366305583098","172333689746750447640181055706745135863","49810702887685588431626092626740255903","122159244357195136257592672787240349962","200915416900325873091092672507666471333","233341778925137734100952155355989792530","149753512965555209015292879519633611543","127855682258650135544031642480579742353","149201959822532762370398242678403913941","195183881814732918883122418756540794781","157836135723829501432628534208557358734","315573956196085501296017697858330558061","98621953539401281077683091160451730339","34183056290755178804957044328146555091","147097768864745665097953187560050553770","79565485170579903222228626003059997293","109755499451070921570115523553497752","222766780501820167014060301415667097979","83772377145282036920175320633349591294","142549715682121202835288963217444880864","293878932591585715621848028831514671976","331553024411102244672153279217221046784","12773358958103158692657403607432258419","97858226354796234715676097049102284263"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-a9913166","target":{"file":"sources/ippcp/crypto_mb/src/sm3/sm3_avx512_mb8.c"},"signature_type":"Line"},{"digest":{"threshold":0.9,"line_hashes":["100182080224825303789053449579206478348","273051130718500638821251135470027157903","338535823344951728592337388311246834420","63981807389373771940680060562806756880"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-b63d0f74","target":{"file":"sources/ippcp/crypto_mb/include/internal/sm3/sm3_common.h"},"signature_type":"Line"},{"digest":{"threshold":0.9,"line_hashes":["74261214726852833234779839923259249514","337643535318477086281523653150498006677","157238224869672923287346174884530793992","78091611924514390479047688589744547519","117404811826664605391591363184498580222","148917495717972961948765887320713663034","67145827510406658424460602860501325027","23134555626811271040062730661690867700","275459870327549217338901565351884269689","324246835812415812439311398751220827771","96035597880449341170817048827523129961","150049189878901676104039328618175628448","317863120294148045986592130849336703791","165793310538028688986464578043762336651","232878644819132554943947885284029203659","324232155887709423274926464976741032987","257895255406930354640676668771513854542"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-bfb10abf","target":{"file":"sources/ippcp/crypto_mb/src/sm3/sm3_update_mb8.c"},"signature_type":"Line"},{"digest":{"threshold":0.9,"line_hashes":["162975435144782112170076814740085221485","186011154121658112520763912661122745282","149428269986561524590656282925269051715","162799662803477057989179335850349915042","208099130815580179810883352782570540030"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-cb7aaf8a","target":{"file":"sources/ippcp/crypto_mb/src/sm4/sm4_ofb_mb16.c"},"signature_type":"Line"},{"digest":{"threshold":0.9,"line_hashes":["234896420878552124625060846871186998330","328263307456570843815065488965101443707","220405283984181306315500265530742737220","207302744430817625545885149090780459551","261533441241528936503088433420329013196","159000643857789816464380670958737217079","118070722689318247415091220620975567526","210169391449860889108031526601322443973","300394629451026715108166964109109545397","203687518161108130339283876748193648606","23149067614414762230281438950182284982","111748619614083955059454646606724522584","157215309390090261447176085229320553226","233412704071370226682730095361806937104","143440497553227468998573800950048712977","40473032100609535342509572050879126460","59236024695842029086493756611927851703","281531775195775461333424949787384780287","109109541413007636594371062762604387882","221364048472202312014360023891152550117","171874964036787856664249516872844843065","164632094174124101683804200599768982961","95857621701452262621422434691896018246","336380833383214665462890480469746527166","186858350769043929503506367336187213719","226394422463586132126271309878578851941","114665484705150978314365704645106882095","332727341367878817333397599272257861504","288256809518608594930593973963629184677","173971266045709373746475773523164052012","240447719495662134016000311419836040425"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-cbb35b3d","target":{"file":"sources/ippcp/crypto_mb/src/sm3/sm3_avx512_mb16.c"},"signature_type":"Line"},{"digest":{"threshold":0.9,"line_hashes":["197769557710177708985827043187553746982","334932662922060185780454668983599952725","186058977057303279443058653683785273269","330798777556666900290156262930926526352","54748527953593387312041375088915704069"]},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-d2797871","target":{"file":"sources/ippcp/crypto_mb/src/sm4/sm4_ecb_mb16.c"},"signature_type":"Line"},{"digest":{"function_hash":"225617385325709814825608387728222641909","length":8848},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-df3467ef","target":{"file":"sources/ippcp/crypto_mb/src/sm3/sm3_avx512_mb16.c","function":"sm3_avx512_mb16"},"signature_type":"Function"},{"digest":{"function_hash":"9761208470400400746248451415455779463","length":3459},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-eab6d99c","target":{"file":"sources/ippcp/crypto_mb/src/sm3/sm3_final_mb16.c","function":"mbx_sm3_final_mb16"},"signature_type":"Function"},{"digest":{"function_hash":"98879338153294576796534313992725064012","length":3068},"source":"https://github.com/intel/ipp-crypto/commit/3ae57715fbc7383ef527cab0b824d736b60fa06d","signature_version":"v1","deprecated":false,"id":"CVE-2022-41646-f3512c4b","target":{"file":"sources/ippcp/crypto_mb/src/sm3/sm3_update_mb8.c","function":"sm3_update_mb8"},"signature_type":"Function"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}