CVE-2016-7054

HIGH

OpenSSL 1.1.0-1.1.0b - Denial of Service via CHACHA20-POLY1305 Cipher Payload Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-7054. PoCs published by Silverfox.

AI-analyzed exploit summary This exploit demonstrates a heap overflow in OpenSSL 1.1.0a and 1.1.0b by negotiating ChaCha20-Poly1305 cipher suites and sending a malformed message with a bad MAC, causing a denial of service (DoS). The PoC uses the tlsfuzzer library to craft a TLS handshake with a tampered payload.

Description

In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue is not considered to be exploitable beyond a DoS.

Exploits (1)

exploitdb WORKING POC
by Silverfox · pythondoslinux
https://www.exploit-db.com/exploits/40899

This exploit demonstrates a heap overflow in OpenSSL 1.1.0a and 1.1.0b by negotiating ChaCha20-Poly1305 cipher suites and sending a malformed message with a bad MAC, causing a denial of service (DoS). The PoC uses the tlsfuzzer library to craft a TLS handshake with a tampered payload.

Classification
Working Poc 100%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: OpenSSL 1.1.0a, 1.1.0b
No auth needed
Prerequisites: OpenSSL 1.1.0a or 1.1.0b with ChaCha20-Poly1305 cipher suite enabled · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94238
Patch, Vendor Advisory x_refsource_confirm
https://www.openssl.org/news/secadv/20161110.txt
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40899/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037261

Scores

CVSS v3 7.5
EPSS 0.3239
EPSS Percentile 98.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-284
Status published
Products (6)
openssl/openssl 1.1.0
openssl/openssl 1.1.0a
openssl/openssl 1.1.0b
OpenSSL/OpenSSL openssl-1.1.0
OpenSSL/OpenSSL openssl-1.1.0a
OpenSSL/OpenSSL openssl-1.1.0b
Published May 04, 2017
Tracked Since Feb 18, 2026