CVE-2026-42767

Source
https://cve.org/CVERecord?id=CVE-2026-42767
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42767.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-42767
Downstream
Related
Published
2026-06-09T16:03:27.435Z
Modified
2026-07-19T07:36:45.028405313Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
NULL Pointer Dereference in CRMF EncryptedValue Decryption
Details

Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.

Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.

An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.

Applications that process untrusted CMP/CRMF messages may be affected.

The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

Database specific
{
    "cwe_ids": [
        "CWE-476"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42767.json",
    "cna_assigner": "openssl"
}
References

Affected packages

Git / github.com/openssl/openssl

Affected ranges

Type
GIT
Repo
https://github.com/openssl/openssl
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.0.21"
        },
        {
            "introduced": "3.4.0"
        },
        {
            "fixed": "3.4.6"
        },
        {
            "introduced": "3.5.0"
        },
        {
            "fixed": "3.5.7"
        },
        {
            "introduced": "3.6.0"
        },
        {
            "fixed": "3.6.3"
        },
        {
            "introduced": "4.0.0-NA"
        },
        {
            "last_affected": "4.0.0-NA"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ],
    "cpe": [
        "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*"
    ]
}

Affected versions

3.*
3.0-POST-CLANG-FORMAT-WEBKIT
3.0-PRE-CLANG-FORMAT-WEBKIT
3.4-POST-CLANG-FORMAT-WEBKIT
3.4-PRE-CLANG-FORMAT-WEBKIT
3.5-POST-CLANG-FORMAT-WEBKIT
3.5-PRE-CLANG-FORMAT-WEBKIT
3.6-POST-CLANG-FORMAT-WEBKIT
3.6-PRE-CLANG-FORMAT-WEBKIT
4.*
4.0.0-NA
openssl-3.*
openssl-3.0.0
openssl-3.0.1
openssl-3.0.10
openssl-3.0.11
openssl-3.0.12
openssl-3.0.13
openssl-3.0.14
openssl-3.0.15
openssl-3.0.16
openssl-3.0.17
openssl-3.0.18
openssl-3.0.19
openssl-3.0.2
openssl-3.0.20
openssl-3.0.3
openssl-3.0.4
openssl-3.0.5
openssl-3.0.6
openssl-3.0.7
openssl-3.0.8
openssl-3.0.9
openssl-3.4.0
openssl-3.4.1
openssl-3.4.2
openssl-3.4.3
openssl-3.4.4
openssl-3.4.5
openssl-3.5.0
openssl-3.5.1
openssl-3.5.2
openssl-3.5.3
openssl-3.5.4
openssl-3.5.5
openssl-3.5.6
openssl-3.6.0
openssl-3.6.1
openssl-3.6.2
openssl-4.*
openssl-4.0.0

Database specific

vanir_signatures
[
    {
        "signature_type": "Function",
        "target": {
            "file": "crypto/crmf/crmf_lib.c",
            "function": "OSSL_CRMF_ENCRYPTEDVALUE_decrypt"
        },
        "deprecated": false,
        "source": "https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d",
        "signature_version": "v1",
        "digest": {
            "function_hash": "91217218025620681749438914001896975009",
            "length": 2457.0
        },
        "id": "CVE-2026-42767-106bce18"
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "crypto/crmf/crmf_lib.c",
            "function": "OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert"
        },
        "deprecated": false,
        "source": "https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046",
        "signature_version": "v1",
        "digest": {
            "function_hash": "325408460393520916772416597402285172584",
            "length": 2492.0
        },
        "id": "CVE-2026-42767-2e365102"
    },
    {
        "digest": {
            "line_hashes": [
                "158143592860499033873604399931203102660",
                "2310307610686490434900170873732564816",
                "166946920779036293788103000554885336837",
                "160560530336034347711027100914902923557",
                "307617896841777165862456063373442756103",
                "150099295707028111203602953360634233926",
                "225656028714529592189036479462720338304",
                "84952586632365817100217631231349827711",
                "139151340687842933703999904366776901818",
                "206543994600228090187663760716588651494",
                "114949461791416633062388642277476779956",
                "50177780468873553555030560247521475161"
            ],
            "threshold": 0.9
        },
        "target": {
            "file": "crypto/crmf/crmf_lib.c"
        },
        "deprecated": false,
        "source": "https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873",
        "id": "CVE-2026-42767-67f1e926",
        "signature_type": "Line",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "crypto/crmf/crmf_lib.c",
            "function": "OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert"
        },
        "deprecated": false,
        "source": "https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774",
        "signature_version": "v1",
        "digest": {
            "function_hash": "233325686147742210662481575423982742364",
            "length": 2139.0
        },
        "id": "CVE-2026-42767-6a92a7c7"
    },
    {
        "digest": {
            "line_hashes": [
                "158143592860499033873604399931203102660",
                "60688306397627978211701846104401847170",
                "77688536731994844037099143947334460932",
                "160001391318980809684469413508905282423",
                "62352660086429031702055047130064202397",
                "338937022658953388516261522269428062787",
                "313096676879358747269849563288427874290",
                "261523757798894084583931286852707949089",
                "175766670349288168436146356470242879454",
                "164276849464106337402847898219872288169",
                "114949461791416633062388642277476779956",
                "50177780468873553555030560247521475161"
            ],
            "threshold": 0.9
        },
        "target": {
            "file": "crypto/crmf/crmf_lib.c"
        },
        "deprecated": false,
        "source": "https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774",
        "id": "CVE-2026-42767-6d7f3b94",
        "signature_type": "Line",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "crypto/crmf/crmf_lib.c"
        },
        "deprecated": false,
        "source": "https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "158143592860499033873604399931203102660",
                "2310307610686490434900170873732564816",
                "166946920779036293788103000554885336837",
                "160560530336034347711027100914902923557",
                "307617896841777165862456063373442756103",
                "150099295707028111203602953360634233926",
                "225656028714529592189036479462720338304",
                "84952586632365817100217631231349827711",
                "139151340687842933703999904366776901818",
                "206543994600228090187663760716588651494",
                "114949461791416633062388642277476779956",
                "50177780468873553555030560247521475161"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-42767-6f387f04"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "crypto/crmf/crmf_lib.c",
            "function": "OSSL_CRMF_ENCRYPTEDVALUE_decrypt"
        },
        "deprecated": false,
        "source": "https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873",
        "digest": {
            "function_hash": "177468829496979591909634834209401852632",
            "length": 2300.0
        },
        "id": "CVE-2026-42767-d047643f",
        "signature_type": "Function"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "crypto/crmf/crmf_lib.c",
            "function": "OSSL_CRMF_ENCRYPTEDVALUE_decrypt"
        },
        "deprecated": false,
        "source": "https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f",
        "digest": {
            "function_hash": "91217218025620681749438914001896975009",
            "length": 2457.0
        },
        "id": "CVE-2026-42767-d61d12de",
        "signature_type": "Function"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "crypto/crmf/crmf_lib.c"
        },
        "deprecated": false,
        "source": "https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "158143592860499033873604399931203102660",
                "60688306397627978211701846104401847170",
                "77688536731994844037099143947334460932",
                "160001391318980809684469413508905282423",
                "307617896841777165862456063373442756103",
                "150099295707028111203602953360634233926",
                "262624842520804075076259156904012189589",
                "261523757798894084583931286852707949089",
                "175766670349288168436146356470242879454",
                "164276849464106337402847898219872288169",
                "114949461791416633062388642277476779956",
                "50177780468873553555030560247521475161"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-42767-e4725b98"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "crypto/crmf/crmf_lib.c"
        },
        "deprecated": false,
        "source": "https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "158143592860499033873604399931203102660",
                "2310307610686490434900170873732564816",
                "166946920779036293788103000554885336837",
                "160560530336034347711027100914902923557",
                "307617896841777165862456063373442756103",
                "150099295707028111203602953360634233926",
                "225656028714529592189036479462720338304",
                "84952586632365817100217631231349827711",
                "139151340687842933703999904366776901818",
                "206543994600228090187663760716588651494",
                "114949461791416633062388642277476779956",
                "50177780468873553555030560247521475161"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-42767-fadb862b"
    }
]
vanir_signatures_modified
"2026-07-14T16:46:15Z"
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42767.json"