CVE-2026-42765

Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain verification enabled when the chain does not have a self-signed trusted anchor, the issuer will be NULL for the last certificate in the chain. A NULL pointer dereference then happens. This issue affects only applications which enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate verification. Both flags are disabled by default. For that reason, we have assigned Low severity to the issue. No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) Resumen del problema: Cuando la verificación de certificado de cadena parcial está habilitada junto con la comprobación de respuesta OCSP para toda la cadena, ocurrirá una desreferencia de NULL si la cadena verificada no tiene un ancla de confianza autofirmada, bloqueando el proceso. Resumen del impacto: Una desreferencia de puntero NULL puede desencadenar un bloqueo que lleva a una Denegación de Servicio para una aplicación. Al realizar la comprobación de respuesta OCSP para certificados en la cadena de verificación, el código siempre intenta acceder al siguiente certificado como emisor. Hay una comprobación para un certificado autofirmado. Sin embargo, con la verificación de cadena parcial habilitada, cuando la cadena no tiene un ancla de confianza autofirmada, el emisor será NULL para el último certificado de la cadena. Entonces ocurre una desreferencia de puntero NULL. Este problema afecta solo a las aplicaciones que habilitan tanto la verificación OCSP de la cadena de certificados (X509_V_FLAG_OCSP_RESP_CHECK_ALL) como la verificación de cadena parcial (X509_V_FLAG_PARTIAL_CHAIN) en la verificación de certificados. Ambas banderas están deshabilitadas por defecto. Por esa razón, hemos asignado una severidad Baja al problema. Ningún módulo FIPS se ve afectado por este problema ya que el código afectado está fuera del límite del módulo FIPS de OpenSSL.

15 Jun 2026, 18:14

Type Values Removed Values Added
CPE cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
References () https://github.com/openssl/openssl/commit/14340b7fa1d444615486bc137014b064e64ec334 - () https://github.com/openssl/openssl/commit/14340b7fa1d444615486bc137014b064e64ec334 - Patch
References () https://github.com/openssl/openssl/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97 - () https://github.com/openssl/openssl/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97 - Patch
References () https://openssl-library.org/news/secadv/20260609.txt - () https://openssl-library.org/news/secadv/20260609.txt - Vendor Advisory
First Time Openssl openssl
Openssl

10 Jun 2026, 08:16

Type Values Removed Values Added
References
  • {'url': 'https://github.com/openssl/security/commit/14340b7fa1d444615486bc137014b064e64ec334', 'source': 'openssl-security@openssl.org'}
  • {'url': 'https://github.com/openssl/security/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97', 'source': 'openssl-security@openssl.org'}
  • () https://github.com/openssl/openssl/commit/14340b7fa1d444615486bc137014b064e64ec334 -
  • () https://github.com/openssl/openssl/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97 -

09 Jun 2026, 21:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

09 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 17:17

Updated : 2026-07-23 08:10


NVD link : CVE-2026-42765

Mitre link : CVE-2026-42765

CVE.ORG link : CVE-2026-42765


JSON object : View

Products Affected

openssl

  • openssl
CWE
CWE-476

NULL Pointer Dereference