CVE-2026-75805: medium-severity vulnerability in OpenSSL
NULL Pointer Dereference in CMP Client Revocation Response Handling
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.2%
exploitation probability
0.2%top 88% of all CVEs
observed exploitation
nono source reports it
Issue summary: A CMP client that requests certificate revocation on the basis
of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when
processing a crafted revocation response.
Impact summary: The NULL pointer dereference happens on a read which
leads to a crash and a Denial of Service for the affected client application.
CWE: CWE-476: NULL-pointer dereference
Description: A CMP client revoking a certificate has to tell the server which
certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the
certificate itself or its issuer name and serial number. This is
'openssl cmp -cmd rr -csr <file>' on the command line, or
OSSL_CMP_exec_RR_ses() with the certificate supplied via
OSSL_CMP_CTX_set1_p10CSR() through the API.
A CSR does not contain the issuer name and serial number of the certificate,
so the client does not send them. A server may optionally name the
certificate it revoked in its response, and the client then compares that
name against what it sent. Having sent neither an issuer name nor a serial
number, it has nothing to compare against, and a server returning a specially
crafted name causes the client to read from a NULL pointer and crash.
The revocation response is checked for valid message protection before
the affected code is reached, so an attacker must be a malicious or
compromised CMP server, or a man-in-the-middle in possession of the
secret used for message protection. Clients that identify the certificate
to be revoked by a certificate or by issuer and serial number rather
than by a PKCS#10 CSR are not affected.
FIPS impact: no
No FIPS modules are affected by this issue, as the CMP protocol
implementation is outside the OpenSSL FIPS module boundary.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products
OpenSSL · OpenSSLRelated CVEs — OpenSSL
In the same product, most dangerous first.
CVE-2022-2068CRITICALThe c_rehash script allows command injectionEPSS 95.4%CVE-2022-3786HIGHX.509 Email Address Variable Length Buffer OverflowEPSS 92.5%CVE-2022-3602HIGHX.509 Email Address 4-byte Buffer OverflowEPSS 90.8%CVE-2021-3711—SM2 Decryption Buffer OverflowEPSS 87.8%CVE-2022-1292CRITICALThe c_rehash script allows command injectionEPSS 82.6%CVE-2023-2650MEDIUMPossible DoS translating ASN.1 object identifiersEPSS 75.1%
References
https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190fhttps://openssl-library.org/news/secadv/20260929.txt