Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42765

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain verification enabled when the chain does not have a self-signed trusted anchor, the issuer will be NULL for the last certificate in the chain. A NULL pointer dereference then happens. This issue affects only applications which enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate verification. Both flags are disabled by default. For that reason, we have assigned Low severity to the issue. No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.

A flaw was found in OpenSSL. When an application is configured with specific non-default settings for certificate verification, including both Online Certificate Status Protocol (OCSP) response checking and partial chain verification, a NULL dereference can occur. This vulnerability can be triggered if the certificate chain lacks a self-signed trusted anchor, causing the application to crash. This leads to a Denial of Service (DoS) for the affected application.

Отчет

This issue is rated as Low impact. A NULL pointer dereference can occur in applications that enable both OCSP response checking for the entire certificate chain and partial chain verification. Since both of these flags are disabled by default in Red Hat products, the risk of exploitation is significantly reduced. This flaw could lead to a Denial of Service if an application is configured with these non-default settings.

Меры по смягчению последствий

To mitigate this issue, ensure that applications do not enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) simultaneously. These flags are disabled by default, and maintaining the default configuration prevents exposure to this flaw. Consult application-specific documentation for details on how to configure certificate verification flags.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10edk2Under investigation
Red Hat Enterprise Linux 10opensslUnder investigation
Red Hat Enterprise Linux 10shimUnder investigation
Red Hat Enterprise Linux 10shim-unsigned-aarch64Under investigation
Red Hat Enterprise Linux 10shim-unsigned-x64Under investigation
Red Hat Enterprise Linux 6opensslUnder investigation
Red Hat Enterprise Linux 7ovmfUnder investigation
Red Hat Enterprise Linux 8compat-openssl10Under investigation
Red Hat Enterprise Linux 8edk2Under investigation
Red Hat Enterprise Linux 8mingw-opensslUnder investigation

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2481889openssl: NULL Dereference in Certificate Verification with OCSP Checking

EPSS

Процентиль: 34%
0.00419
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain verification enabled when the chain does not have a self-signed trusted anchor, the issuer will be NULL for the last certificate in the chain. A NULL pointer dereference then happens. This issue affects only applications which enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate verifi...

CVSS3: 7.5
nvd
2 месяца назад

Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain verification enabled when the chain does not have a self-signed trusted anchor, the issuer will be NULL for the last certificate in the chain. A NULL pointer dereference then happens. This issue affects only applications which enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate verifi

msrc
4 дня назад

Описание отсутствует

CVSS3: 7.5
debian
2 месяца назад

Issue summary: When a partial-chain certificate verification is enable ...

CVSS3: 7.5
github
2 месяца назад

Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When performing OCSP response checking for certificates in the verification chain, the code always tries to access the next certificate as the issuer. There is a check for a self-signed certificate. However with the partial chain verification enabled when the chain does not have a self-signed trusted anchor, the issuer will be NULL for the last certificate in the chain. A NULL pointer dereference then happens. This issue affects only applications which enable both OCSP verification of the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial chain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate ver...

EPSS

Процентиль: 34%
0.00419
Низкий

5.9 Medium

CVSS3