CVE-2026-22796
Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
27/01/2026
Última modificación:
27/01/2026
Descripción
*** Pendiente de traducción *** Issue summary: A type confusion vulnerability exists in the signature<br />
verification of signed PKCS#7 data where an ASN1_TYPE union member is<br />
accessed without first validating the type, causing an invalid or NULL<br />
pointer dereference when processing malformed PKCS#7 data.<br />
<br />
Impact summary: An application performing signature verification of PKCS#7<br />
data or calling directly the PKCS7_digest_from_attributes() function can be<br />
caused to dereference an invalid or NULL pointer when reading, resulting in<br />
a Denial of Service.<br />
<br />
The function PKCS7_digest_from_attributes() accesses the message digest attribute<br />
value without validating its type. When the type is not V_ASN1_OCTET_STRING,<br />
this results in accessing invalid memory through the ASN1_TYPE union, causing<br />
a crash.<br />
<br />
Exploiting this vulnerability requires an attacker to provide a malformed<br />
signed PKCS#7 to an application that verifies it. The impact of the<br />
exploit is just a Denial of Service, the PKCS7 API is legacy and applications<br />
should be using the CMS API instead. For these reasons the issue was<br />
assessed as Low severity.<br />
<br />
The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,<br />
as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module<br />
boundary.<br />
<br />
OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.
Impacto
Puntuación base 3.x
5.30
Gravedad 3.x
MEDIA
Referencias a soluciones, herramientas e información
- https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4
- https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49
- https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12
- https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e
- https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2
- https://openssl-library.org/news/secadv/20260127.txt



