CVE-2026-28388
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
07/04/2026
Last modified:
10/04/2026
Description
Issue summary: When a delta CRL that contains a Delta CRL Indicator extension<br />
is processed a NULL pointer dereference might happen if the required CRL<br />
Number extension is missing.<br />
<br />
Impact summary: A NULL pointer dereference can trigger a crash which<br />
leads to a Denial of Service for an application.<br />
<br />
When CRL processing and delta CRL processing is enabled during X.509<br />
certificate verification, the delta CRL processing does not check<br />
whether the CRL Number extension is NULL before dereferencing it.<br />
When a malformed delta CRL file is being processed, this parameter<br />
can be NULL, causing a NULL pointer dereference.<br />
<br />
Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in<br />
the verification context, the certificate being verified to contain a<br />
freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and<br />
an attacker to provide a malformed CRL to an application that processes it.<br />
<br />
The vulnerability is limited to Denial of Service and cannot be escalated to<br />
achieve code execution or memory disclosure. For that reason the issue was<br />
assessed as Low severity according to our Security Policy.<br />
<br />
The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,<br />
as the affected code is outside the OpenSSL FIPS module boundary.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e
- https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139
- https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3
- https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8
- https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726
- https://openssl-library.org/news/secadv/20260407.txt



