CVE-2026-42766

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
09/06/2026
Last modified:
23/07/2026

Description

Issue summary: A specially crafted password-encrypted CMS message<br /> can trigger a NULL pointer dereference during CMS decryption.<br /> <br /> Impact summary: This NULL pointer dereference leads to an application crash<br /> and a Denial of Service.<br /> <br /> The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as<br /> OPTIONAL in the ASN.1 specification and may therefore be absent in specially<br /> crafted inputs. During the password-based CMS decryption the OpenSSL<br /> CMS implementation dereferences this field without first checking whether it<br /> was present.<br /> <br /> An attacker who supplies such a CMS message to an application performing<br /> password-based CMS decryption can trigger an application crash, leading to<br /> a Denial of Service.<br /> <br /> Applications that process password-encrypted CMS messages may be affected.<br /> <br /> The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this<br /> issue, as the affected code is outside the OpenSSL FIPS module boundary.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 1.0.2 (including) 1.0.2zq (excluding)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 1.1.1 (including) 1.1.1zh (excluding)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.21 (excluding)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.4.0 (including) 3.4.6 (excluding)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.5.0 (including) 3.5.7 (excluding)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.6.0 (including) 3.6.3 (excluding)
cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*