Null Pointer Dereference Vulnerability in OpenSSL CMP Client Application
CVE-2026-42767
What is CVE-2026-42767?
The OpenSSL CMP client is susceptible to a NULL pointer dereference vulnerability, which can occur when processing a specially crafted response from an attacker-controlled Certificate Management Protocol (CMP) server. This vulnerability can lead to a crash of the CMP client application, thus resulting in a Denial of Service. An attacker could exploit this by sending a crafted CMP response that contains an improperly formatted CertRepMessage. It is crucial for users of affected versions of OpenSSL to apply the patches provided in recent updates to mitigate this security risk. Notably, FIPS modules in versions 4.0, 3.6, 3.5, 3.4, and 3.0 are not impacted by this issue.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.1
OpenSSL 3.6.0 < 3.6.3
OpenSSL 3.5.0 < 3.5.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved