PT-2026-81299 · Openssl+3 · Openssl+3

·

CVE-2026-14457

·

Published

2026-08-25

·

Updated

2026-09-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description A NULL pointer dereference can occur in server or client configurations where RFC7250 Raw Public Keys (RPKs) are enabled and only a private key is configured locally without an associated certificate. This happens when a remote peer requests raw public keys and includes the signature algorithms cert TLS extension. This issue can lead to a Denial of Service (DoS) due to an application abort. A NULL pointer dereference is a software error where the program attempts to read or write to a memory address that is NULL, typically causing the application to crash.
Recommendations Update to an updated release. As a mitigation measure, configure a corresponding certificate (self-signed or signed by a CA) alongside the private key to ensure the signature algorithms cert extension is handled reliably.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14457
OPENSUSE-SU-2026:11623-1
OPENSUSE-SU-2026:21744-1
RHSA-2026:59635
RHSA-2026:59641
USN-8678-1

Affected Products

Freebsd
Linuxmint
Openssl
Ubuntu