Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-28390

Опубликовано: 07 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

A flaw was found in OpenSSL. A remote attacker could exploit this vulnerability by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message. During the processing of a KeyTransportRecipientInfo with RSA-OAEP encryption, the system attempts to access an optional parameter field without first verifying its presence. This leads to a NULL pointer dereference, which can cause applications processing the attacker-controlled CMS data to crash, resulting in a Denial of Service (DoS).

Отчет

This CVE has been rated as moderate by redhat because the vulnerability is limited to a denial-of-service condition caused by a NULL pointer dereference in OpenSSL CMS processing, without evidence of memory corruption or code execution, furthermore the Affected functionality is niche. The vulnerable path requires: CMS/S/MIME processing, specifically CMS_decrypt(), with RSA-OAEP KeyTransportRecipientInfo. Many OpenSSL consumers never use CMS APIs, never process S/MIME, or do not decrypt attacker-controlled CMS objects. So exposure is far narrower than a generic TLS parsing vulnerability.

Меры по смягчению последствий

Applications that process Cryptographic Message Syntax (CMS) EnvelopedData messages should be configured to only accept input from trusted sources. Restricting network access to services that process untrusted CMS data can also reduce exposure to this Denial of Service vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Cluster Operatorconfidential-clusters-beta/confidential-cluster-operator-bundleAffected
Confidential Cluster Operatorredhat-user-workloads/attestation-key-registerAffected
Confidential Cluster Operatorredhat-user-workloads/buildrootAffected
Confidential Cluster Operatorredhat-user-workloads/compute-pcrsAffected
Confidential Cluster Operatorredhat-user-workloads/confidential-cluster-operatorAffected
Confidential Cluster Operatorredhat-user-workloads/registration-serverAffected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-operator-bundleAffected
Confidential Compute Attestationredhat-user-workloads/osc-monitorAffected
Confidential Compute Attestationredhat-user-workloads/osc-monitor-v1-10Not affected
Confidential Compute Attestationredhat-user-workloads/osc-operatorAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2456314openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing

EPSS

Процентиль: 60%
0.01027
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryp...

CVSS3: 7.5
nvd
4 месяца назад

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 5.9
msrc
4 месяца назад

Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo

CVSS3: 7.5
debian
4 месяца назад

Issue summary: During processing of a crafted CMS EnvelopedData messag ...

suse-cvrf
4 дня назад

Security update for openssl-1_0_0

EPSS

Процентиль: 60%
0.01027
Низкий

7.5 High

CVSS3