CVE-2026-42767

Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service. An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client. Applications that process untrusted CMP/CRMF messages may be affected. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) Resumen del problema: Un servidor CMP (Certificate Management Protocol) controlado por el atacante podría desencadenar una desreferencia de puntero NULL en una aplicación cliente CMP. Resumen del impacto: Una desreferencia de puntero NULL causa un fallo de la aplicación y una denegación de servicio. Un atacante que controla un servidor CMP (o actuando como un man-in-the-middle) podría elaborar una respuesta CMP que contiene un CertRepMessage CRMF (Certificate Request Message Format) con una estructura EncryptedValue donde el campo symmAlg tiene un OID de algoritmo pero no un campo de parámetros. Cuando el cliente CMP de OpenSSL procesa esta respuesta, la desreferencia NULL ocurre, causando un fallo del cliente CMP. Las aplicaciones que procesan mensajes CMP/CRMF no confiables pueden verse afectadas. Los módulos FIPS en 4.0, 3.6, 3.5, 3.4 y 3.0 no se ven afectados por este problema, ya que el código afectado está fuera del límite del módulo FIPS de OpenSSL.

16 Jun 2026, 02:58

Type Values Removed Values Added
First Time Openssl openssl
Openssl
CPE cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
References () https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046 - () https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046 - Patch
References () https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774 - () https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774 - Patch
References () https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f - () https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f - Patch
References () https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873 - () https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873 - Patch
References () https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d - () https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d - Patch
References () https://openssl-library.org/news/secadv/20260609.txt - () https://openssl-library.org/news/secadv/20260609.txt - Vendor Advisory

10 Jun 2026, 08:16

Type Values Removed Values Added
References
  • {'url': 'https://github.com/openssl/security/commit/61a86a8cd73546c9fea916f3d304c1293e05c046', 'source': 'openssl-security@openssl.org'}
  • {'url': 'https://github.com/openssl/security/commit/665d5254083affde9982efca7c41dd01cacc8774', 'source': 'openssl-security@openssl.org'}
  • {'url': 'https://github.com/openssl/security/commit/810b722f772652ad48042bcc7ab07e3414b11d0f', 'source': 'openssl-security@openssl.org'}
  • {'url': 'https://github.com/openssl/security/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873', 'source': 'openssl-security@openssl.org'}
  • {'url': 'https://github.com/openssl/security/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d', 'source': 'openssl-security@openssl.org'}
  • () https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046 -
  • () https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774 -
  • () https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f -
  • () https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873 -
  • () https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d -

09 Jun 2026, 21:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9

09 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 17:17

Updated : 2026-07-23 08:10


NVD link : CVE-2026-42767

Mitre link : CVE-2026-42767

CVE.ORG link : CVE-2026-42767


JSON object : View

Products Affected

openssl

  • openssl
CWE
CWE-476

NULL Pointer Dereference