{"id":"CVE-2022-48437","details":"An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error is returned. This behavior occurs when there is an installed verification callback that instructs the verifier to continue upon detecting an invalid certificate.","modified":"2026-08-27T10:10:39.514286Z","published":"2023-04-12T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48437.json","unresolved_ranges":[{"extracted_events":[{"fixed":"3.6.1"},{"fixed":"7.2"}],"source":"DESCRIPTION"}],"cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.6.1-relnotes.txt"},{"type":"WEB","url":"https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/001_x509.patch.sig"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48437.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-48437"},{"type":"FIX","url":"https://github.com/openbsd/src/commit/4f94258c65a918ee3d8670e93916d15bf879e6ec"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libressl/portable","events":[{"introduced":"0"},{"fixed":"aa1f9b11664ac41f304b638ec259d937fee6281e"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:openbsd:libressl:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.6.1"}]}}],"versions":["v3.6.0","v3.5.1","v3.5.0","v3.4.0","v3.3.2","v3.3.1","v3.3.0","v3.2.1","v3.2.0","v3.1.0","v3.0.1","v3.0.0","v2.9.0","v2.8.1","v2.8.0","v2.7.1","v2.7.0","v2.6.2","v2.6.1","v2.6.0","v2.5.2","v2.5.1","v2.5.0","v2.4.1","v2.4.0","v2.3.2","v2.3.1","v2.3.0","v2.2.2","v2.2.1","v2.2.0","v2.1.4","v2.1.3","v2.1.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48437.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/openbsd/src","events":[{"introduced":"0"},{"fixed":"4f94258c65a918ee3d8670e93916d15bf879e6ec"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"vanir_signatures_modified":"2026-08-27T10:10:39Z","vanir_signatures":[{"target":{"file":"lib/libcrypto/x509/x509_verify.c"},"deprecated":false,"digest":{"line_hashes":["81719393747868085048422088394428365045","299459420622645230707451842010917572902","85799397585808107703557449779900920705","247294790526753992351928178221485709230","234504098091462367986816544589286488793","150242622989381968931317115240370013598","337902517269935143438647334868026160433","273293703492565897298378858890108262716","267881243648794546275961912710928915656","9904423386351368814165591720792026490","315556154492084895725381442474426831272","118772061436964868308665180013205082866","147866471546058165665915264692044477993","168292816833079554680712598173915841368"],"threshold":0.9},"id":"CVE-2022-48437-23ff3b02","signature_type":"Line","signature_version":"v1","source":"https://github.com/openbsd/src/commit/4f94258c65a918ee3d8670e93916d15bf879e6ec"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/openbsd/src/commit/4f94258c65a918ee3d8670e93916d15bf879e6ec","target":{"file":"lib/libcrypto/x509/x509_verify.c","function":"x509_verify_ctx_add_chain"},"deprecated":false,"digest":{"function_hash":"86510228362593344781340589714722190578","length":881},"id":"CVE-2022-48437-3b4ec1cd"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48437.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}