PT-2026-81299 · Openssl+3 · Openssl+3
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSSL (affected versions not specified)
Description
A NULL pointer dereference can occur in server or client configurations where RFC7250 Raw Public Keys (RPKs) are enabled and only a private key is configured locally without an associated certificate. This happens when a remote peer requests raw public keys and includes the
signature algorithms cert TLS extension. This issue can lead to a Denial of Service (DoS) due to an application abort. A NULL pointer dereference is a software error where the program attempts to read or write to a memory address that is NULL, typically causing the application to crash.Recommendations
Update to an updated release.
As a mitigation measure, configure a corresponding certificate (self-signed or signed by a CA) alongside the private key to ensure the
signature algorithms cert extension is handled reliably.Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd
Linuxmint
Openssl
Ubuntu