PT-2026-102659 · Openssl · Openssl

·

CVE-2026-84783

·

Published

2026-09-29

·

Updated

2026-10-08

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL version 4.0
Description A use-after-free read occurs when multiple threads concurrently use the same X.509 certificate for the first time. OpenSSL caches decoded X.509v3 extension values in two phases: computation under a read lock and installation under a write lock. Since read locks do not exclude other readers, multiple threads may compute the cache simultaneously. A thread acquiring the write lock may free values installed by a previous thread that is still using pointers to that memory, leading to a process crash and Denial of Service. This issue specifically affects trusted CA certificates shared across connections in multi-threaded TLS clients or TLS servers that request client certificates.
Recommendations Upgrade to OpenSSL 4.0.3.

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84783

Affected Products

Openssl