PT-2026-47844 · Openssl+5 · Openssl+5

·

CVE-2026-45447

·

Published

2026-06-09

·

Updated

2026-08-19

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL version 4.0 OpenSSL version 3.6 OpenSSL version 3.5 OpenSSL version 3.4 OpenSSL version 3.0 OpenSSL version 1.1.1 OpenSSL version 1.0.2
Description A use-after-free condition occurs during PKCS#7 signature verification when processing a specially crafted PKCS#7 or S/MIME signed message. If the SignedData digestAlgorithms field is present as an empty ASN.1 SET, the PKCS7 verify() function may incorrectly free a BIO (Basic Input/Output abstraction) owned by the caller. A subsequent attempt by the application to use or free this BIO via BIO free() leads to memory corruption, process crashes, or potentially remote code execution. This issue affects applications using OpenSSL PKCS#7 APIs, while those using CMS APIs are not affected. FIPS modules in versions 4.0, 3.6, 3.5, 3.4, and 3.0 are not impacted as the affected code resides outside the FIPS module boundary.
Recommendations Update OpenSSL to the latest patched version for versions 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2. As a temporary workaround, avoid using the PKCS7 verify() function to process PKCS#7 or S/MIME signed messages until the update is applied.

Exploit

Fix

DoS

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:25237
ALSA-2026:25239
ALSA-2026:26275
ALSA-2026:36215
ALSA-2026:44438
AZL-89811
AZL-89864
AZL-92837
CVE-2026-45447
JLSEC-2026-1145
OESA-2026-2748
OESA-2026-2749
OESA-2026-2750
OESA-2026-2781
OESA-2026-2782
OESA-2026-2783
OESA-2026-2784
OPENSUSE-SU-2026:11023-1
OPENSUSE-SU-2026:21005-1
RHSA-2026:25237
RHSA-2026:25239
RHSA-2026:26275
RHSA-2026:35869
RHSA-2026:36215
RHSA-2026:44438
SUSE-SU-2026:22100-1
SUSE-SU-2026:22132-1
SUSE-SU-2026:22143-1
SUSE-SU-2026:22251-1
SUSE-SU-2026:22315-1
SUSE-SU-2026:2392-1
SUSE-SU-2026:2393-1
SUSE-SU-2026:2396-1
SUSE-SU-2026:2397-1
SUSE-SU-2026:2399-1
SUSE-SU-2026:2403-1
SUSE-SU-2026:2404-1
SUSE-SU-2026:2405-1
SUSE-SU-2026:2409-1
SUSE-SU-2026:2410-1
SUSE-SU-2026:2411-1
SUSE-SU-2026:2412-1
SUSE-SU-2026:2598-1
SUSE-SU-2026:2614-1
SUSE-SU-2026:2621-1
SUSE-SU-2026:2648-1
SUSE-SU-2026:2662-1
USN-8414-1
USN-8414-2

Affected Products

Freebsd
Ibm Aix
Linuxmint
Openssl
Rocky Linux
Ubuntu