Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Aydinmercan

#40153of 57,643
7.5Total CVSS
Vulnerabilities · 1
PT-2026-102659
7.5
2026-09-29
Openssl · Openssl · CVE-2026-84783
**Name of the Vulnerable Software and Affected Versions** OpenSSL version 4.0 **Description** A use-after-free read occurs when multiple threads concurrently use the same X.509 certificate for the first time. OpenSSL caches decoded X.509v3 extension values in two phases: computation under a read lock and installation under a write lock. Since read locks do not exclude other readers, multiple threads may compute the cache simultaneously. A thread acquiring the write lock may free values installed by a previous thread that is still using pointers to that memory, leading to a process crash and Denial of Service. This issue specifically affects trusted CA certificates shared across connections in multi-threaded TLS clients or TLS servers that request client certificates. **Recommendations** Upgrade to OpenSSL 4.0.3.