{"id":"CVE-2026-45447","summary":"Heap Use-After-Free in the PKCS7_verify() Function","details":"Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.","modified":"2026-08-19T09:06:16.097691Z","published":"2026-06-09T16:03:32.914Z","related":["ALSA-2026:25237","ALSA-2026:25239","ALSA-2026:26275","ALSA-2026:36215","ALSA-2026:44438","CGA-v8wj-6895-grc3","SUSE-SU-2026:22100-1","SUSE-SU-2026:22132-1","SUSE-SU-2026:22143-1","SUSE-SU-2026:22251-1","SUSE-SU-2026:22315-1","SUSE-SU-2026:2392-1","SUSE-SU-2026:2393-1","SUSE-SU-2026:2396-1","SUSE-SU-2026:2397-1","SUSE-SU-2026:2399-1","SUSE-SU-2026:2403-1","SUSE-SU-2026:2404-1","SUSE-SU-2026:2405-1","SUSE-SU-2026:2409-1","SUSE-SU-2026:2410-1","SUSE-SU-2026:2411-1","SUSE-SU-2026:2412-1","SUSE-SU-2026:2598-1","SUSE-SU-2026:2614-1","SUSE-SU-2026:2621-1","SUSE-SU-2026:2648-1","SUSE-SU-2026:2662-1","openSUSE-SU-2026:11023-1","openSUSE-SU-2026:21005-1"],"database_specific":{"cna_assigner":"openssl","cwe_ids":["CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45447.json"},"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:25237"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:25239"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:26275"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:26319"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:29197"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34102"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:35869"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36215"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36217"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:39009"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:39012"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:39981"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:44438"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:47735"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:47737"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-45447"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45447.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45447"},{"type":"ADVISORY","url":"https://openssl-library.org/news/secadv/20260609.txt"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2481898"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssl/openssl","events":[{"introduced":"e818b74be2170fbe957a07b0da4401c2b694b3b8"},{"fixed":"e818b74be2170fbe957a07b0da4401c2b694b3b8"},{"introduced":"e04bd3433fd84e1861bf258ea37928d9845e6a86"},{"fixed":"e04bd3433fd84e1861bf258ea37928d9845e6a86"},{"introduced":"89cd17a031e022211684eb7eb41190cf1910f9fa"},{"fixed":"51ea949dc1436e865935b47874b21a3bb31a102e"},{"introduced":"98acb6b02839c609ef5b837794e08d906d965335"},{"fixed":"c5ea1cc227fd60afae8ac4b9438690bbe4888f79"},{"introduced":"636dfadc70ce26f2473870570bfd9ec352806b1d"},{"fixed":"8cf17aaeb4599f8af87fefd810b5b5fee90fe69e"},{"introduced":"7b371d80d959ec9ab4139d09d78e83c090de9779"},{"fixed":"aae016bfd52fcad2bc9657c2c782cfdf73b1ed5f"},{"introduced":"11b7b6ea3b65a584e1d31408ed1bdb139465cffd"},{"fixed":"3aad5eb7af4de4ee0633c30a8541a54d9bbde63c"},{"fixed":"7d4a980c62258c5910cc883936e0c8dbab4d75a8"},{"fixed":"9dfd688ad2290fc5075cacbc9bf0c9a93eefed54"},{"fixed":"a541ae8bfe849a30cc885e8780715c0f488e496c"},{"fixed":"c505d7559da5d5f9f2c3913c6883a5562ce7273e"}],"database_specific":{"extracted_events":[{"introduced":"1.0.2"},{"fixed":"1.0.2zq"},{"introduced":"1.1.1"},{"fixed":"1.1.1zh"},{"introduced":"3.0.0"},{"fixed":"3.0.21"},{"introduced":"3.4.0"},{"fixed":"3.4.6"},{"introduced":"3.5.0"},{"fixed":"3.5.7"},{"introduced":"3.6.0"},{"fixed":"3.6.3"},{"introduced":"4.0.0-NA"},{"last_affected":"4.0.0-NA"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*"]}}],"versions":["4.0.0-NA","openssl-4.0.0","openssl-3.0.20","openssl-3.4.5","openssl-3.5.6","openssl-3.6.2","openssl-3.0.19","openssl-3.4.4","openssl-3.5.5","openssl-3.6.1","3.4-POST-CLANG-FORMAT-WEBKIT","3.0-POST-CLANG-FORMAT-WEBKIT","3.4-PRE-CLANG-FORMAT-WEBKIT","3.5-POST-CLANG-FORMAT-WEBKIT","3.0-PRE-CLANG-FORMAT-WEBKIT","3.5-PRE-CLANG-FORMAT-WEBKIT","3.6-POST-CLANG-FORMAT-WEBKIT","3.6-PRE-CLANG-FORMAT-WEBKIT","openssl-3.6.0","openssl-3.0.18","openssl-3.4.3","openssl-3.5.4","openssl-3.5.3","openssl-3.5.2","openssl-3.0.17","openssl-3.4.2","openssl-3.5.1","openssl-3.5.0","openssl-3.0.16","openssl-3.4.1","openssl-3.4.0","openssl-3.0.15","openssl-3.0.14","openssl-3.0.13","openssl-3.0.12","openssl-3.0.11","openssl-3.0.10","openssl-3.0.9","openssl-3.0.8","openssl-3.0.7","openssl-3.0.6","openssl-3.0.5","openssl-3.0.4","openssl-3.0.3","openssl-3.0.2","openssl-3.0.1","openssl-3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45447.json","vanir_signatures_modified":"2026-08-19T09:06:16Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8","target":{"file":"crypto/pkcs7/pk7_smime.c"},"deprecated":false,"digest":{"line_hashes":["70032386994102898015755781116675591173","231173238294476209958437975937461189092","91004330705699031067436524277598537423","234478855118283170924508843710538205766","252012625435324001085572340899543118347","60599586766355096168968970453558347210","94071772432497829554597961740548536547","10972650511968472694408939394497980996","69586036514364750636852680906528639129","157497159777392996731945355893177824278"],"threshold":0.9},"id":"CVE-2026-45447-07564722"},{"signature_version":"v1","source":"https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c","target":{"file":"crypto/pkcs7/pk7_smime.c"},"deprecated":false,"digest":{"line_hashes":["70032386994102898015755781116675591173","231173238294476209958437975937461189092","91004330705699031067436524277598537423","234478855118283170924508843710538205766","252012625435324001085572340899543118347","60599586766355096168968970453558347210","94071772432497829554597961740548536547","10972650511968472694408939394497980996","69586036514364750636852680906528639129","157497159777392996731945355893177824278"],"threshold":0.9},"id":"CVE-2026-45447-88a48a55","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["70032386994102898015755781116675591173","231173238294476209958437975937461189092","91004330705699031067436524277598537423","234478855118283170924508843710538205766","252012625435324001085572340899543118347","60599586766355096168968970453558347210","94071772432497829554597961740548536547","10972650511968472694408939394497980996","69586036514364750636852680906528639129","157497159777392996731945355893177824278"],"threshold":0.9},"id":"CVE-2026-45447-b549f08e","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c","target":{"file":"crypto/pkcs7/pk7_smime.c"}},{"signature_version":"v1","source":"https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54","target":{"file":"crypto/pkcs7/pk7_smime.c"},"deprecated":false,"digest":{"line_hashes":["151496904140441974460168482169374190024","92179460093030619455591542092510111715","60382042702447683296284768934212051145","5235401096140011172643223403337748039","68476233529675048551545910092045734077","135472893131710710891792272165369874557","144388576385066123595834036136006620631","251569583518298411383983956510462999062","190752638376984200658169048788492801771","100442701798321830557371459503827921141","157868922838337151802955969179465392317","247133924118207300622477622521703740882"],"threshold":0.9},"id":"CVE-2026-45447-b9e52ddb","signature_type":"Line"},{"digest":{"line_hashes":["70032386994102898015755781116675591173","231173238294476209958437975937461189092","91004330705699031067436524277598537423","234478855118283170924508843710538205766","252012625435324001085572340899543118347","60599586766355096168968970453558347210","94071772432497829554597961740548536547","10972650511968472694408939394497980996","69586036514364750636852680906528639129","157497159777392996731945355893177824278"],"threshold":0.9},"id":"CVE-2026-45447-be71f95d","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e","target":{"file":"crypto/pkcs7/pk7_smime.c"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e04bd3433fd84e1861bf258ea37928d9845e6a86","target":{"file":"include/openssl/opensslv.h"},"deprecated":false,"digest":{"line_hashes":["28170854778703993674264004058177114599","73132526844288570625317440636111911761","177405411499435185068645597737938634778","224809958623850711330610094965797758930","295554444428855106393106961197201359586"],"threshold":0.9},"id":"CVE-2026-45447-c377fa22"},{"source":"https://github.com/openssl/openssl/commit/e818b74be2170fbe957a07b0da4401c2b694b3b8","target":{"file":"crypto/opensslv.h"},"deprecated":false,"digest":{"line_hashes":["251633914150035957322733061977107206211","338514574181828579838011565939158652696","76638288692106140328510055542557597351","142922657400765574308962710386922248045","71649992455794854055653842592139575350","65527166711110472566013424527579064967","253196866009476977787139000804413898733","172177136897997206866313011107384691461"],"threshold":0.9},"id":"CVE-2026-45447-e051451f","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}