๐Ÿ” CVE Alert

CVE-2026-75805

MEDIUM 5.3

NULL Pointer Dereference in CMP Client Revocation Response Handling

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.

CWE CWE-476
Vendor openssl
Product openssl
Ecosystems
Industries
TechnologySecurity
Published Sep 29, 2026
Last Updated Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for openssl openssl

Be the first to know when new medium vulnerabilities affecting openssl openssl are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenSSL / OpenSSL
4.0.0 < 4.0.3 3.6.0 < 3.6.5 3.5.0 < 3.5.9 3.4.0 < 3.4.8 3.0.0 < 3.0.23

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
openssl-library.org: https://openssl-library.org/news/secadv/20260929.txt github.com: https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7 github.com: https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166 github.com: https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3 github.com: https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f

Credits

๐Ÿ” Bhabani Sankar Das Bhabani Sankar Das Norbert Pocs