{"id":"CVE-2026-42767","summary":"NULL Pointer Dereference in CRMF EncryptedValue Decryption","details":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.","modified":"2026-08-12T16:24:22.292173Z","published":"2026-06-09T16:03:27.435Z","related":["ALSA-2026:25237","ALSA-2026:25239","CGA-39mr-jp3c-8ccj","SUSE-SU-2026:22251-1","SUSE-SU-2026:22315-1","SUSE-SU-2026:22437-1","SUSE-SU-2026:22449-1","SUSE-SU-2026:2648-1","SUSE-SU-2026:3004-1","SUSE-SU-2026:3005-1","SUSE-SU-2026:3094-1","openSUSE-SU-2026:11023-1","openSUSE-SU-2026:21005-1"],"database_specific":{"cwe_ids":["CWE-476"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42767.json","cna_assigner":"openssl"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42767.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42767"},{"type":"ADVISORY","url":"https://openssl-library.org/news/secadv/20260609.txt"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssl/openssl","events":[{"introduced":"89cd17a031e022211684eb7eb41190cf1910f9fa"},{"fixed":"51ea949dc1436e865935b47874b21a3bb31a102e"},{"introduced":"98acb6b02839c609ef5b837794e08d906d965335"},{"fixed":"c5ea1cc227fd60afae8ac4b9438690bbe4888f79"},{"introduced":"636dfadc70ce26f2473870570bfd9ec352806b1d"},{"fixed":"8cf17aaeb4599f8af87fefd810b5b5fee90fe69e"},{"introduced":"7b371d80d959ec9ab4139d09d78e83c090de9779"},{"fixed":"aae016bfd52fcad2bc9657c2c782cfdf73b1ed5f"},{"introduced":"11b7b6ea3b65a584e1d31408ed1bdb139465cffd"},{"fixed":"61a86a8cd73546c9fea916f3d304c1293e05c046"},{"fixed":"665d5254083affde9982efca7c41dd01cacc8774"},{"fixed":"810b722f772652ad48042bcc7ab07e3414b11d0f"},{"fixed":"b90ff3b1bd33b1c18e6a09936d097c2eddef8873"},{"fixed":"e6f912907fc2ec82a0fd07aae55172c5e5e3d90d"}],"database_specific":{"cpe":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.0.21"},{"introduced":"3.4.0"},{"fixed":"3.4.6"},{"introduced":"3.5.0"},{"fixed":"3.5.7"},{"introduced":"3.6.0"},{"fixed":"3.6.3"},{"introduced":"4.0.0-NA"},{"last_affected":"4.0.0-NA"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["4.0.0-NA","openssl-4.0.0","openssl-3.0.20","openssl-3.4.5","openssl-3.5.6","openssl-3.6.2","openssl-3.0.19","openssl-3.4.4","openssl-3.5.5","openssl-3.6.1","3.4-POST-CLANG-FORMAT-WEBKIT","3.0-POST-CLANG-FORMAT-WEBKIT","3.4-PRE-CLANG-FORMAT-WEBKIT","3.5-POST-CLANG-FORMAT-WEBKIT","3.0-PRE-CLANG-FORMAT-WEBKIT","3.5-PRE-CLANG-FORMAT-WEBKIT","3.6-POST-CLANG-FORMAT-WEBKIT","3.6-PRE-CLANG-FORMAT-WEBKIT","openssl-3.6.0","openssl-3.0.18","openssl-3.4.3","openssl-3.5.4","openssl-3.5.3","openssl-3.5.2","openssl-3.0.17","openssl-3.4.2","openssl-3.5.1","openssl-3.5.0","openssl-3.0.16","openssl-3.4.1","openssl-3.4.0","openssl-3.0.15","openssl-3.0.14","openssl-3.0.13","openssl-3.0.12","openssl-3.0.11","openssl-3.0.10","openssl-3.0.9","openssl-3.0.8","openssl-3.0.7","openssl-3.0.6","openssl-3.0.5","openssl-3.0.4","openssl-3.0.3","openssl-3.0.2","openssl-3.0.1","openssl-3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42767.json","vanir_signatures_modified":"2026-08-12T16:24:22Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d","target":{"file":"crypto/crmf/crmf_lib.c","function":"OSSL_CRMF_ENCRYPTEDVALUE_decrypt"},"deprecated":false,"digest":{"function_hash":"91217218025620681749438914001896975009","length":2457},"id":"CVE-2026-42767-106bce18","signature_type":"Function"},{"id":"CVE-2026-42767-2e365102","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046","target":{"file":"crypto/crmf/crmf_lib.c","function":"OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert"},"deprecated":false,"digest":{"function_hash":"325408460393520916772416597402285172584","length":2492}},{"target":{"file":"crypto/crmf/crmf_lib.c"},"deprecated":false,"digest":{"line_hashes":["158143592860499033873604399931203102660","2310307610686490434900170873732564816","166946920779036293788103000554885336837","160560530336034347711027100914902923557","307617896841777165862456063373442756103","150099295707028111203602953360634233926","225656028714529592189036479462720338304","84952586632365817100217631231349827711","139151340687842933703999904366776901818","206543994600228090187663760716588651494","114949461791416633062388642277476779956","50177780468873553555030560247521475161"],"threshold":0.9},"id":"CVE-2026-42767-67f1e926","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873"},{"deprecated":false,"digest":{"function_hash":"233325686147742210662481575423982742364","length":2139},"id":"CVE-2026-42767-6a92a7c7","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774","target":{"file":"crypto/crmf/crmf_lib.c","function":"OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert"}},{"target":{"file":"crypto/crmf/crmf_lib.c"},"deprecated":false,"digest":{"line_hashes":["158143592860499033873604399931203102660","60688306397627978211701846104401847170","77688536731994844037099143947334460932","160001391318980809684469413508905282423","62352660086429031702055047130064202397","338937022658953388516261522269428062787","313096676879358747269849563288427874290","261523757798894084583931286852707949089","175766670349288168436146356470242879454","164276849464106337402847898219872288169","114949461791416633062388642277476779956","50177780468873553555030560247521475161"],"threshold":0.9},"id":"CVE-2026-42767-6d7f3b94","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774"},{"deprecated":false,"digest":{"line_hashes":["158143592860499033873604399931203102660","2310307610686490434900170873732564816","166946920779036293788103000554885336837","160560530336034347711027100914902923557","307617896841777165862456063373442756103","150099295707028111203602953360634233926","225656028714529592189036479462720338304","84952586632365817100217631231349827711","139151340687842933703999904366776901818","206543994600228090187663760716588651494","114949461791416633062388642277476779956","50177780468873553555030560247521475161"],"threshold":0.9},"id":"CVE-2026-42767-6f387f04","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d","target":{"file":"crypto/crmf/crmf_lib.c"}},{"deprecated":false,"digest":{"function_hash":"177468829496979591909634834209401852632","length":2300},"id":"CVE-2026-42767-d047643f","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873","target":{"file":"crypto/crmf/crmf_lib.c","function":"OSSL_CRMF_ENCRYPTEDVALUE_decrypt"}},{"target":{"file":"crypto/crmf/crmf_lib.c","function":"OSSL_CRMF_ENCRYPTEDVALUE_decrypt"},"deprecated":false,"digest":{"function_hash":"91217218025620681749438914001896975009","length":2457},"id":"CVE-2026-42767-d61d12de","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f"},{"deprecated":false,"digest":{"line_hashes":["158143592860499033873604399931203102660","60688306397627978211701846104401847170","77688536731994844037099143947334460932","160001391318980809684469413508905282423","307617896841777165862456063373442756103","150099295707028111203602953360634233926","262624842520804075076259156904012189589","261523757798894084583931286852707949089","175766670349288168436146356470242879454","164276849464106337402847898219872288169","114949461791416633062388642277476779956","50177780468873553555030560247521475161"],"threshold":0.9},"id":"CVE-2026-42767-e4725b98","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046","target":{"file":"crypto/crmf/crmf_lib.c"}},{"signature_version":"v1","source":"https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f","target":{"file":"crypto/crmf/crmf_lib.c"},"deprecated":false,"digest":{"line_hashes":["158143592860499033873604399931203102660","2310307610686490434900170873732564816","166946920779036293788103000554885336837","160560530336034347711027100914902923557","307617896841777165862456063373442756103","150099295707028111203602953360634233926","225656028714529592189036479462720338304","84952586632365817100217631231349827711","139151340687842933703999904366776901818","206543994600228090187663760716588651494","114949461791416633062388642277476779956","50177780468873553555030560247521475161"],"threshold":0.9},"id":"CVE-2026-42767-fadb862b","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}