Openssl · Openssl · CVE-2026-84783
**Name of the Vulnerable Software and Affected Versions**
OpenSSL version 4.0
**Description**
A use-after-free read occurs when multiple threads concurrently use the same X.509 certificate for the first time. OpenSSL caches decoded X.509v3 extension values in two phases: computation under a read lock and installation under a write lock. Since read locks do not exclude other readers, multiple threads may compute the cache simultaneously. A thread acquiring the write lock may free values installed by a previous thread that is still using pointers to that memory, leading to a process crash and Denial of Service. This issue specifically affects trusted CA certificates shared across connections in multi-threaded TLS clients or TLS servers that request client certificates.
**Recommendations**
Upgrade to OpenSSL 4.0.3.