PT-2026-81304 · Openssl+3 · Openssl+3

·

CVE-2026-63073

·

Published

2026-08-25

·

Updated

2026-09-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description An issue exists in the CMP response validation where the ossl cmp msg check update() function converts a peer-supplied sender distinguished name using X509 NAME oneline() and passes it directly as the format argument to ERR raise data(). Because percent characters are preserved during conversion, a malicious or intercepted CMP endpoint can provide a sender DN containing format specifiers like %s or %n. These specifiers reach BIO vsnprintf() without matching variadic arguments, causing the client to dereference or write through unrelated stack contents. This leads to a denial of service by crashing the CMP client, specifically when the client enforces an expected sender or uses a pinned server certificate.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

DoS

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-97950
CVE-2026-63073
OPENSUSE-SU-2026:11623-1
OPENSUSE-SU-2026:21744-1
USN-8678-1

Affected Products

Freebsd
Linuxmint
Openssl
Ubuntu